FTDownloader.exe

FTDownloader

Cool Mirage ltd.

This is part of a CoolMirage installatation, a potentially unwanted program (PUP) that display ads on the computer. The application FTDownloader.exe by Cool Mirage ltd has been detected as adware by 3 anti-malware scanners. This is a setup program which is used to install the application. This file is typically installed with the program FTDownloader by FTDownloader.com which is a potentially unwanted software program. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities.
Publisher:
Cool Mirage ltd.  (signed and verified)

Product:
FTDownloader

Version:
1.1.1.1

MD5:
9d7eff65b77b4ece48cf5a9f58a405e2

SHA-1:
8a5ba613ff3d8367579bcc1f76ba4cec1548ca26

SHA-256:
b84d36d4012e67167b2602216fe75a8e7973984373859b62e38703ee74984b5e

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
4/20/2024 2:50:23 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Downloader-TPG [PUP]
2014.9-131223

Reason Heuristics
PUP.CoolMirageltd.M
14.8.7.18

VIPRE Antivirus
CoolMirage Ltd
23700

File size:
2.5 MB (2,629,680 bytes)

Product version:
1.1.1.1

Copyright:
Copyright © 2013

Original file name:
FTDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\ftdownloader.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/14/2012 1:00:00 AM

Valid to:
11/15/2014 12:59:59 AM

Subject:
CN=Cool Mirage ltd., O=Cool Mirage ltd., STREET=ogarit 39, L=tel aviv, S=tel aviv, PostalCode=69016, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FC28659CC8073606EF4D09A1994B1AD0

File PE Metadata
Compilation timestamp:
3/14/2013 7:22:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:73LnK0iueiUCCCGMzAtww2NlRp3j2JVpK761Y8Ee1mtzV3P9J+bz+ukUIbsHvrr3:i7ueiUCCC9Etww2yJTp1XmtxedkzirEI

Entry address:
0x27DEBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.5 MB (2,605,056 bytes)

The file FTDownloader.exe has been discovered within the following program.

FTDownloader  by FTDownloader.com
Publisher's description - “FT Downloader is a FREE download manager that can increase the speed and stability of your downloads by up to 5 times. Resume and schedule downloads and comprehensive error recovery. It is a powerful, yet easy-to-use download manager you can rely on.”
ftdownloader.com
75% remove it
 
Powered by Should I Remove It?

The file FTDownloader.exe has been seen being distributed by the following URL.

Remove FTDownloader.exe - Powered by Reason Core Security