download_adobe_premiere_elements_13.exe

Download Assistant

Arvato Digital Services LLC

The application download_adobe_premiere_elements_13.exe by Arvato Digital Services has been detected as a potentially unwanted program by 3 anti-malware scanners. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from red.protexis.net.
Publisher:
Arvato Digital Services LLC  (signed and verified)

Product:
Download Assistant

Version:
1.5.1.10

MD5:
a1f5df578f58ec141ee2d16c90addbea

SHA-1:
1b4b3e7b563e6b55bbfa23e9f014a22a860ea6a4

SHA-256:
2a3fe03aa75b575dbdda8161fe0abad936b16c8124eace01097b744087664a30

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 6:34:18 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Dropper.Gen
7.11.30.172

F-Secure
Riskware.Gen:Variant.Application.Bundler
11.2015-25-12_6

Reason Heuristics
PUP.Arvato.DownloadAssistant.Meta (L)
15.12.28.23

File size:
1.7 MB (1,771,888 bytes)

Product version:
1.5.1.10

Copyright:
© 2006 Protexis Inc.

Original file name:
DownloadAssistant.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\ie\{random}\download_adobe_premiere_elements_13.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
8/27/2014 5:00:00 PM

Valid to:
8/27/2017 4:59:59 PM

Subject:
CN=Arvato Digital Services LLC, O=Arvato Digital Services LLC, L=Valencia, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2CB1B9F18A38469B1ED4C0E0361568AD

File PE Metadata
Compilation timestamp:
2/15/2013 10:03:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:PV+G/Mcsd9h1yMMCzcL71L9+fKQV7x3nFBSTpeXXAcoV:PB/Mwzj71ofK691QpeXQl

Entry address:
0xC352B

Entry point:
E8, 6C, BC, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, 7C, DB, 55, 00, 75, 02, F3, C3, E9, EE, BC, 00, 00, 8B, C1, 83, 60, 04, 00, 83, 60, 08, 00, C7, 00, 84, E9, 52, 00, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 56, 57, 8B, F9, C7, 07, 84, E9, 52, 00, 8B, 03, 85, C0, 74, 26, 50, E8, 3C, 02, 00, 00, 8B, F0, 46, 56, E8, C8, 33, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 12, FF, 33, 56, 50, E8, 81, 9F, 00, 00, 83, C4, 0C, EB, 04, 83, 67, 04, 00, C7, 47, 08, 01, 00, 00, 00, 8B, C7, 5F, 5E, 5B, 5D, C2, 04, 00, 8B, FF, 55...
 
[+]

Entropy:
6.4543

Code size:
1.1 MB (1,132,544 bytes)

The file download_adobe_premiere_elements_13.exe has been seen being distributed by the following URL.

Remove download_adobe_premiere_elements_13.exe - Powered by Reason Core Security