cd.exe

Gerenciador de Download

The application cd.exe has been detected as a potentially unwanted program by 28 anti-malware scanners. This is a setup program which is used to install the application. This setup program installs potentially unwanted software on the user's PC at the same time as the expected/marketing software, without adequate consent. The program is typically installed via a form of malvertising The file has been seen being downloaded from www.baixarmidia.com and multiple other hosts.
Publisher:
Gerenciador de Download

Product:
Gerenciador de Download

Version:
1.0.0

MD5:
afc1e581a1ec5acf98b08b8635bee8fb

SHA-1:
956f81cddbcb50164f430fa712690b45c1f70944

SHA-256:
47ba75c83c8c338d6a8aa2350123a2c13fdf9d105c3517c58add1ceabb751eb5

Scanner detections:
28 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 3:29:13 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Rogue
7.1.1

AhnLab V3 Security
PUP/Win32.Downloader
2013.09.13

Avira AntiVirus
Adware/Dealeem.B
7.11.102.44

avast!
Win32:Adware-AON [PUP]
2014.9-140728

Baidu Antivirus
Malware.Win32.SecurityDownloader
4.0.3.14728

Bitdefender
Trojan.Generic.KDV.907577
1.0.20.1045

Clam AntiVirus
WIN.Downloader.Agent-1281
0.98/18155

Comodo Security
Application.Win32.PCMega.L
16925

Emsisoft Anti-Malware
Trojan.Generic.KDV.907577
8.14.07.28.09

ESET NOD32
Win32/Adware.PCMega.J.Gen
8.8792

Fortinet FortiGate
Adware/DownloadWare
7/28/2014

F-Prot
W32/Adware.AKQE
v6.4.7.1.166

G Data
Trojan.Generic.KDV.907577
14.7.22

IKARUS anti.virus
SoftwareBundler
t3scan.2.0.127

K7 AntiVirus
Adware
13.172.9570

Kaspersky
not-a-virus:AdWare.Win32.DownloadWare
14.0.0.3493

Malwarebytes
Adware.Bundler
v2014.07.28.09

McAfee
Downloader-FMJ
5600.7056

Microsoft Security Essentials
SoftwareBundler:Win32/Protlerdob
1.163.1557.0

nProtect
Trojan/W32.Agent.1008582
13.09.12.03

Panda Antivirus
Trj/Dtcontx.C
14.07.28.09

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.2.10

Sophos
Generic PUA JF
4.91

Trend Micro House Call
TROJ_SPNR.08CM13
7.2.209

Trend Micro
TROJ_SPNR.08CM13
10.465.28

Vba32 AntiVirus
AdWare.DownloadWare
3.12.24.2

VIPRE Antivirus
Trojan.Win32.Generic
21406

ViRobot
Backdoor.Win32.A.ZAccess.394869
2011.4.7.4223

File size:
984.9 KB (1,008,582 bytes)

Product version:
1.0.0

Copyright:
© Gerenciador de Download

Original file name:
download.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\cd.exe

File PE Metadata
Compilation timestamp:
5/6/2009 2:23:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:7x4Mi4+EaWyZDAbKh6tBoJU0DuF4jovaVGMwhJE/Clpzwu+:TcEaWjrjiA4jova8Mz/Clpzwu+

Entry address:
0x8B902

Entry point:
E8, 2D, 79, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, 33, C9, 3B, 04, CD, 90, 46, 4D, 00, 74, 12, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0C, 6A, 0D, 58, C3, 8B, 04, CD, 94, 46, 4D, 00, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, C3, E8, 5E, 3D, 00, 00, 85, C0, 75, 06, B8, F8, 47, 4D, 00, C3, 83, C0, 08, C3, E8, 4B, 3D, 00, 00, 85, C0, 75, 06, B8, FC, 47, 4D, 00, C3, 83, C0, 0C, C3, 56, E8, E7, FF, FF, FF, 8B, 4C, 24, 08, 51, 89, 08, E8, 8D, FF, FF, FF, 59, 8B, F0...
 
[+]

Code size:
684 KB (700,416 bytes)

The file cd.exe has been seen being distributed by the following 3 URLs.

http://www.baixarmidia.com/ids/.../The Sims 2 8 Expansões – PC.zip

Remove cd.exe - Powered by Reason Core Security