baldosas de caucho jardindirecto.com.exe

Maxiget Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application baldosas de caucho jardindirecto.com.exe by Maxiget Limited has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
Maxiget Limited  (signed and verified)

Version:
3, 3, 50, 0

MD5:
fff797b68edd84ee51a97d011331b7f1

SHA-1:
0e1d1f3cc6b3adb162f6fb3193f3508b5ab6a0fb

SHA-256:
87e88ea146af6cef3792e7866db36419e89eb493967c51970812359907231d93

Scanner detections:
13 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 6:23:53 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen
7.11.169.230

AVG
Generic
2015.0.3368

Dr.Web
Adware.Downware.1751
9.0.1.05190

ESET NOD32
Win32/4Shared.U potentially unwanted application
7.0.302.0

G Data
Win32.Application.4shared
14.8.24

K7 AntiVirus
Unwanted-Program
13.183.13198

McAfee
PUP-FNX
5600.7024

NANO AntiVirus
Riskware.Win32.Downware.ddwsbl
0.28.2.61861

Panda Antivirus
Trj/Genetic.gen
14.08.29.01

Reason Heuristics
PUP.MaxigetLimited.e
14.8.29.1

Sophos
4Share Downloader
4.98

VIPRE Antivirus
Threat.4150696
32210

File size:
451.7 KB (462,560 bytes)

Product version:
3, 3, 50, 0

Copyright:
2014

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\baldosas de caucho jardindirecto.com.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
6/3/2014 2:41:06 AM

Valid to:
8/15/2016 12:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
043F9C868704FA

File PE Metadata
Compilation timestamp:
7/30/2014 4:19:37 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:ZtO8gkKra3H/lyN3ZaZLoX/9+JUeEc9qjmNDy/Tcjcgff6NfNd3zom:ZA8WolyiZLE/9+JxtAQD8L1fj3t

Entry address:
0x27FF8

Entry point:
E8, A9, 91, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, E8, 8B, 44, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 5C, A2, 44, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 58, E4, 43, 00, 68, 00, 01, 00, 00, 53, FF, 15, 6C, C1, 43, 00, 85, C0, 74, 08, 89, 3D, 5C, A2, 44, 00, EB, 15, FF, 15, C4, C0, 43, 00, 83, F8, 78, 75, 0A, C7, 05, 5C, A2, 44, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Code size:
233.5 KB (239,104 bytes)

Remove baldosas de caucho jardindirecto.com.exe - Powered by Reason Core Security