download.exe

Gerenciador de Download

The application download.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from www.baixarmidia.com.
Publisher:
Gerenciador de Download

Product:
Gerenciador de Download

Version:
1.0.0

MD5:
f83ac99418b68044d22015245f224421

SHA-1:
9cb593aaf3fbd4096175ad9487380ed6a8251397

SHA-256:
ee0e2e4b28c4de9c0a250ae542787f9463917771dc6b09b9476c1bfe450b56d2

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 5:17:12 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-AON [PUP]
2014.9-151105

Bitdefender
Trojan.Generic.KDV.907577
1.0.20.1545

Clam AntiVirus
WIN.Downloader.Agent-1281
0.98/18155

F-Prot
W32/Adware.AKQE
v6.4.7.1.166

herdProtect (fuzzy)
2015.11.5.10

K7 AntiVirus
Adware
13.172.9570

Kaspersky
not-a-virus:AdWare.Win32.DownloadWare
14.0.0.1168

Malwarebytes
Adware.Bundler
v2015.11.05.10

McAfee
Downloader-FMJ
5600.6591

nProtect
Trojan/W32.Agent.1008582
13.09.12.03

Reason Heuristics
Threat.Win.Reputation.IMP
15.9.10.17

Trend Micro House Call
TROJ_SPNR.08CM13
7.2.309

File size:
985 KB (1,008,600 bytes)

Product version:
1.0.0

Copyright:
© Gerenciador de Download

Original file name:
download.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\download.exe

File PE Metadata
Compilation timestamp:
5/6/2009 2:23:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:Ax4Mi4+EaWyZDAbKh6tBoJU0DuF4jovaVGMwhJE/ClpzwuO:kcEaWjrjiA4jova8Mz/ClpzwuO

Entry address:
0x8B902

Entry point:
E8, 2D, 79, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, 33, C9, 3B, 04, CD, 90, 46, 4D, 00, 74, 12, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0C, 6A, 0D, 58, C3, 8B, 04, CD, 94, 46, 4D, 00, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, C3, E8, 5E, 3D, 00, 00, 85, C0, 75, 06, B8, F8, 47, 4D, 00, C3, 83, C0, 08, C3, E8, 4B, 3D, 00, 00, 85, C0, 75, 06, B8, FC, 47, 4D, 00, C3, 83, C0, 0C, C3, 56, E8, E7, FF, FF, FF, 8B, 4C, 24, 08, 51, 89, 08, E8, 8D, FF, FF, FF, 59, 8B, F0...
 
[+]

Code size:
684 KB (700,416 bytes)

The file download.exe has been seen being distributed by the following URL.

Remove download.exe - Powered by Reason Core Security