java.exe

Mindad media Ltd.

The application java.exe by Mindad media has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Mindad media Ltd.  (signed and verified)

MD5:
569419111802fb2be6f42f7bbb29521b

SHA-1:
0023ff9bf1737deba086e88c3918457f6673656d

SHA-256:
00b24bc3ed359b27d0788236153ef09f3a1b4eb18d076ae476d1bf965dd6f1e7

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Analysis date:
4/19/2024 4:53:59 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MultiBundle.M
2015.0.3496

Dr.Web
Adware.Downware.2081
9.0.1.0113

ESET NOD32
Win32/OutBrowse
8.9711

K7 AntiVirus
Unwanted-Program
13.176.11861

Malwarebytes
PUP.Optional.Mindad
v2014.04.23.10

McAfee
Adware-OutBrowse
5600.7152

NANO AntiVirus
Trojan.Win32.Generic.cthmwf
0.28.0.59492

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Mindadmedia.E
14.8.7.21

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
Trojan.Win32.Generic
28534

File size:
105.2 KB (107,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\java.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/5/2013 1:00:00 AM

Valid to:
8/6/2014 12:59:59 AM

Subject:
CN=Mindad media Ltd., O=Mindad media Ltd., STREET=hamenofim 9, STREET=herzeliya, L=herzeliya, S=herzeliya, PostalCode=46725, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0E7140EE5347CFF2FBDBE59A34386099

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:rgXdZt9P6D3XJmC+Nm5Ky/9XO3jR0eWSzUu/0W:re34V+IUQ9OzRgW/c

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6777

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove java.exe - Powered by Reason Core Security