install_install_virtualdj_home_v7.0.5.exe

The application install_install_virtualdj_home_v7.0.5.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from cdn.msdwnld.com.
MD5:
b0ffba1625c3c73f13444436d70a72bb

SHA-1:
27bdf864b681642f74088692cb8aab33fdc045e4

SHA-256:
79cca18e1c0881122bfca261e4e435d5cac13d6ea467d4d27edd158b4ad56614

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
4/19/2024 11:26:23 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.Toolbar.Babylon
4.0.3.131126

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/18155

Dr.Web
Adware.Downware.908
9.0.1.0240

ESET NOD32
Win32/Toolbar.Babylon
7.8998

McAfee
Artemis!B0FFBA1625C3
5600.7180

SUPERAntiSpyware
Trojan.Agent/Gen-Startpage
10705

Trend Micro House Call
TROJ_GEN.F47V0824
7.2.240

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

File size:
184.3 KB (188,729 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\install_install_virtualdj_home_v7.0.5.exe

File PE Metadata
Compilation timestamp:
8/30/2011 8:46:02 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.21

CTPH (ssdeep):
3072:VBsB7O1RK7YDkesp1gJC45liBpuLtk2VUY2+9ycKl0UOdEzosKzzFaw8GKtV/QCf:VkSK7YQl7jo1k22Y24ngfevs6v47Ylq

Entry address:
0x4105

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, FF, 15, 74, 73, 7A, 00, C7, 04, 24, 01, 80, 00, 00, FF, 15, 58, 74, 7A, 00, 53, C7, 04, 24, 00, 00, 00, 00, FF, 15, 98, 74, 7A, 00, 56, A3, 6C, 53, 7A, 00, C7, 04, 24, 08, 00, 00, 00, E8, 8B, 3B, 00, 00, A3, C8, 53, 7A, 00, 8D, 85, 84, FE, FF, FF, 57, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A9, B2, 40, 00, FF, 15, AC, 74, 7A, 00, 83, EC, 14, C7, 44, 24, 04, AA, B2, 40, 00, C7...
 
[+]

Entropy:
7.5960

Code size:
32.5 KB (33,280 bytes)

The file install_install_virtualdj_home_v7.0.5.exe has been seen being distributed by the following URL.

Remove install_install_virtualdj_home_v7.0.5.exe - Powered by Reason Core Security