jdownloader_0.9.dl.exe

One Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application jdownloader_0.9.dl.exe by One Installer has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from download.oneinstaller.com.
Publisher:
One Installer LLC  (signed and verified)

MD5:
192a5ab87f8c0d57916c26881dbbbbb3

SHA-1:
e7a67e6155400032af9b1968c42ee21abbd027b5

SHA-256:
41a000b859c38f6a730e0b5503e71dc79a35917c95c7d0c9589bb469e5fc6c49

Scanner detections:
14 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/13/2025 11:49:52 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Adware-KQ [PUP]
150319-1

AVG
OneInstaller
2016.0.3119

Dr.Web
Adware.Downware.1265
9.0.1.05190

ESET NOD32
multiple threats
7.0.302.0

G Data
NSIS.Adware.Lollipop
15.5.25

IKARUS anti.virus
PUA.Lollipop
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15799

Kaspersky
not-a-virus:Downloader.Win32.Agent
15.0.0.543

NANO AntiVirus
Trojan.Win32.Siggen5.cthmqx
0.30.24.1357

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Reason Heuristics
Threat.Installer.OneInstaller
15.5.4.17

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.15502

VIPRE Antivirus
Threat.4786531
39676

File size:
649.1 KB (664,712 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\jdownloader_0.9.dl.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
6/13/2013 10:51:12 AM

Valid to:
1/31/2014 8:35:46 PM

Subject:
CN=One Installer LLC, O=One Installer LLC, L=Wilmington, S=DE, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280B63CF38934E

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:40LHpmd8jVv9DgNTFmiIozK7YyVJqi0vv7NCsqBUAT0RjTh1H55f:4YMd8pxgnm/oz5YF0bN3gQRnDH55

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file jdownloader_0.9.dl.exe has been seen being distributed by the following URL.

Remove jdownloader_0.9.dl.exe - Powered by Reason Core Security