install554279.exe

GoforFiles

Righway Technologies, Inc

This is the Via Advertising bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application install554279.exe by Righway Technologies, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the YourFile Downloader installer. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘GoforFilesInstaller Starter’.
Publisher:
http://www.goforfiles.com/  (signed by Righway Technologies, Inc)

Product:
GoforFiles

Version:
1, 0, 0, 464

MD5:
7bd5fc59a35962f9951b5d175b89c0b3

SHA-1:
b10ae78f5f5148248855357371aeeda8448d7b4d

SHA-256:
00cbf679bc1b01645b0aca8317208afd83abeb1b8c768a711ae2d8af3512f133

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 4:41:46 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Via Advertising.RighwayTechnologies.Bundler (M)
16.2.13.20

File size:
6.8 MB (7,167,864 bytes)

Product version:
2,0,0,0

Copyright:
Copyright http://www.goforfiles.com/ (C) 2012

Original file name:
GoforFiles.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
YourFile Downloader

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\install554279.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/22/2012 5:30:00 AM

Valid to:
8/23/2015 5:29:59 AM

Subject:
CN="Righway Technologies, Inc", O="Righway Technologies, Inc", STREET="1740 H Dell Range Blvd #281", L=Cheyenne, S=Wyoming, PostalCode=82009, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0089B8C147F063769F8D685962C161E027

File PE Metadata
Compilation timestamp:
4/17/2014 2:37:39 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:OmraDWj6jD0rBfPg8d55riRJ4jTYi5JyTga:O3Wj6ihX5WRbUyL

Entry address:
0x33946

Entry point:
E8, CE, CD, 00, 00, E9, 89, FE, FF, FF, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, E4, 7B, 46, 00, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, E0, 5C, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24, 95, C0, 3A, 43, 00, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72, 0C, 83, E0, 03, 03, C8, FF, 24, 85, D4, 39...
 
[+]

Entropy:
7.9242  (probably packed)

Code size:
312.5 KB (320,000 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
GoforFilesInstaller Starter

Command:
"C:\users\{user}\appdata\local\temp\install554279.exe" -startup


Remove install554279.exe - Powered by Reason Core Security