limewir.exe

Setup

Dey yazilim ve internet hizmetleri san. tic. ltd. sti.

The application limewir.exe, “WesternDigital Setup” by Dey yazilim ve internet hizmetleri san. tic. ltd. sti has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
WesternDigital  (signed by Dey yazilim ve internet hizmetleri san. tic. ltd. sti.)

Product:
Setup

Description:
WesternDigital Setup

Version:
1.1.2.0

MD5:
4f9d02288f674f1158df2e7ece956271

SHA-1:
313d49c2f81b97c1624c0e93ab5a50c45631df20

SHA-256:
7e298f9dc22cfb764622e17d8b41642fc04cd6df490aeb3717ae3c74d373796f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 9:37:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize.Deyyazilimveinternethizmetlerisanticsti.Installer (M)
16.3.8.11

File size:
465.2 KB (476,376 bytes)

Product version:
1.1.2.0

Copyright:
WesternDigital

Trademarks:
WesternDigital

Original file name:
WesternDigital.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\limewir.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/12/2014 5:00:00 AM

Valid to:
3/13/2015 4:59:59 AM

Subject:
CN=Dey yazilim ve internet hizmetleri san. tic. ltd. sti., O=Dey yazilim ve internet hizmetleri san. tic. ltd. sti., STREET=kuloglu mah alyon gecidi sok, STREET=beyoglu, L=istanbul, S=istanbul, PostalCode=34433, C=TR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD3AA42CD883A6D47CC56CDA9837EB85

File PE Metadata
Compilation timestamp:
3/11/2015 2:33:05 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:CS/J1s0ldUmx/bLbYnwch3SoMGsgL7GZOsLa30hTbJ3BYU9:CS/J1sGdUmx/bwnwcco/nGZY091t

Entry address:
0x6370E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
390 KB (399,360 bytes)

Remove limewir.exe - Powered by Reason Core Security