aomtradutor 1.1.exe

Get your downloads

Maxiget Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application aomtradutor 1.1.exe by Maxiget Limited has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer.
Publisher:
Company #1  (signed by Maxiget Limited)

Product:
Get your downloads

Version:
3, 0, 16, 0

MD5:
55b9e1244ca700506a53ffcd2fccd577

SHA-1:
13ac8911f51b1ffd74847c24bfb3a4e1012157d9

SHA-256:
8cbc95efdb4ca5796392623ec264291c17ea2a1e92508c7924ac4a2580dadaad

Scanner detections:
9 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/27/2024 11:40:08 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Delta.H.17
7.11.111.144

ESET NOD32
Win32/Maxiget (variant)
8.9015

K7 AntiVirus
Unwanted-Program
13.173.10112

McAfee
Artemis!55B9E1244CA7
5600.7140

Reason Heuristics
PUP.MaxigetLimited.O
14.8.7.21

Sophos
4Share Downloader
4.94

SUPERAntiSpyware
Trojan.Agent/Gen-Downloader
10625

Trend Micro House Call
TROJ_GEN.F47V1030
7.2.124

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
137 KB (140,304 bytes)

Product version:
3, 0, 16, 0

Copyright:
Copyright (C) 2013

Trademarks:
TM(c)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\aomtradutor 1.1.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
8/15/2013 3:41:32 AM

Valid to:
8/15/2016 3:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
045BA815265145

File PE Metadata
Compilation timestamp:
10/16/2013 8:12:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:TpZFCFqqw38YzQIIIiGee637+rOFHPvw2EI:vaqqy1RLiGhU2KHwzI

Entry address:
0x9893

Entry point:
E8, 1B, 4E, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24...
 
[+]

Code size:
73 KB (74,752 bytes)

Remove aomtradutor 1.1.exe - Powered by Reason Core Security