google-chrome.exe

Quick Downloader

The Adlogica setup manager, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application google-chrome.exe by Quick Downloader has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the Adlogica Quick Downloader installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.downloaddesktop5.com.
Publisher:
Quick Downloader  (signed and verified)

MD5:
1ba740a0f0b9b99320c428cdbb1dd0a5

SHA-1:
1c82af9ea6f1109912a7054855d25a5ffa2599af

SHA-256:
89a3334c8a1b29c7b4a5f0aacabdb0000520774b7b4276a7bec1951caa6254d0

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/13/2024 4:47:25 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.201.216

AVG
Downloader
2016.0.3227

Bitdefender
MemScan:Application.Bundler.JU
1.0.20.80

Dr.Web
Trojan.Packed.28678
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BS potentially unwanted application
7.0.302.0

Fortinet FortiGate
W32/Agent.BS!tr
1/16/2015

F-Secure
Riskware.MemScan:Application.Bundler.JU
5.13.68

G Data
MemScan:Application.Bundler.JU
15.1.24

K7 AntiVirus
Unwanted-Program
13.191.14667

Kaspersky
not-a-virus:AdWare.MSIL.OutBrowse
15.0.0.543

Malwarebytes
PUP.Optional.OutBrowse
v2015.01.16.01

McAfee
Artemis!591DF37B3C00
5600.6883

MicroWorld eScan
MemScan:Application.Bundler.JU
16.0.0.48

Reason Heuristics
PUP.Adlogica.QuickDownloader
15.1.16.13

Sophos
PUA 'OutBrowse' (of type Adware)
5.09

Trend Micro House Call
Suspici.AF8C44A8
7.2.16

VIPRE Antivirus
Threat.4786018
36694

File size:
584.3 KB (598,360 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adlogica Quick Downloader (using Nullsoft Install System)

Language:
Language Neutral

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/11/2014 6:00:00 PM

Valid to:
8/11/2017 5:59:59 PM

Subject:
CN=Quick Downloader, O=Quick Downloader, STREET="96 Jessie St, 4th Floor", L=San Francisco, S=CA, PostalCode=94105, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0087CE63C7728E982ECA2980DCA8DDE091

File PE Metadata
Compilation timestamp:
12/5/2009 3:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:czHB93XssyqQDXf8Nj9LnFosV2QgkdCAeYSkTrdN:czMr7GJJpOlT8P

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9676

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file google-chrome.exe has been seen being distributed by the following URL.

Remove google-chrome.exe - Powered by Reason Core Security