java.exe

The application java.exe has been detected as a potentially unwanted program by 29 anti-malware scanners. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
MD5:
e6bc1cc5b5cc01247f492c1f31894b16

SHA-1:
fb96a54d0558db58bf41256ca200f389410bfc7c

SHA-256:
3d94c6bc564a35dc5f14716bb9611da083149b56e6fb334121beda0e22cfb07a

Scanner detections:
29 / 68

Status:
Potentially unwanted

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Analysis date:
4/26/2024 5:09:36 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.DomaIQ.3
922

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
2014.07.25

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

avast!
Win32:DomaIQ-CC [PUP]
140617-1

AVG
Adware DomaIQ_r.G
2015.0.3400

Bitdefender
Gen:Variant.Application.Bundler.DomaIQ.3
1.0.20.1045

Clam AntiVirus
Win.Trojan.Domaiq-10
0.98/19185

Dr.Web
Trojan.Damaged.1
9.0.1.05190

ESET NOD32
Win32/DomaIQ.BB potentially unwanted application
8.7.0.302.0

F-Prot
W32/DomaIQ.E.gen
v6.4.7.1.166

F-Secure
Adware:W32/DomaIQ
11.2014-28-07_2

G Data
Gen:Variant.Application.Bundler.DomaIQ
14.7.24

IKARUS anti.virus
AdWare.DomaIQ
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.181.12834

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3493

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.07.28.08

McAfee
CryptDomaIQ
5600.7056

Microsoft Security Essentials
Threat.Undefined
1.179.972.0

MicroWorld eScan
Gen:Variant.Application.Bundler.DomaIQ.3
15.0.0.627

NANO AntiVirus
Riskware.Win32.Lolipop.cvxwob
0.28.2.60990

nProtect
Trojan-Clicker/W32.Agent.396288.D
14.07.24.01

Panda Antivirus
Trj/Genetic.gen
14.07.28.08

Quick Heal
Adware.DomaIQ.BT5
7.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.7.28.8

Rising Antivirus
PE:Malware.DomaIQ!6.165C
23.00.65.14726

Sophos
DomainIQ pay-per install
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10456

VIPRE Antivirus
Threat.4150696
31208

File size:
384.9 KB (394,168 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\java.exe

File PE Metadata
Compilation timestamp:
3/18/2014 4:57:57 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:rOKPXi+cp/iI5KUQoRTHAgMd4l1Xt2aHw1Yy1bBuu86zLxYmt:d/Po/mUQoRTHkdcXt2aQCyWuRzLTt

Entry address:
0x3056

Entry point:
E8, 57, 2A, 00, 00, E9, 7F, FE, FF, FF, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B, C1, C3, 8D, 41, FE, 8B, 4C, 24, 04, 2B, C1...
 
[+]

Entropy:
6.2953

Code size:
37 KB (37,888 bytes)

Remove java.exe - Powered by Reason Core Security