multiplyroi_tomtom-home.exe

Groovecom

The application multiplyroi_tomtom-home.exe by Groovecom has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files5.mirror6.net.
Publisher:
Groovecom  (signed and verified)

MD5:
57ebfaf67219a41a980d4ae1d01f672b

SHA-1:
4d2e8f3ce40ac08e58bbe2a9d18b93a3e90f513a

SHA-256:
8764d181a1ec90e9050c33e56f98cb8ab274357d71c9830645090f52ad565f1b

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/25/2024 6:27:07 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.LH
5821840

avast!
DownloadAdmin-U [Adw]
151219-0

Clam AntiVirus
Win.Adware.Downloadadmin-1
0.98/21211

Dr.Web
Adware.DAdmin.151
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.LH
10.0.0.5366

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
7.0.302.0

Norman
Application.Bundler.LH
17.12.2015 06:34:11

Reason Heuristics
PUP.DownloadAdmin.Groovecom.Installer (M)
15.12.31.18

Sophos
PUA 'Download Admin'
5.22

VIPRE Antivirus
Threat.4783369
46020

File size:
912.6 KB (934,528 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\multiplyroi_tomtom-home.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/25/2014 6:00:00 PM

Valid to:
2/25/2017 5:59:59 PM

Subject:
CN=Groovecom, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Groovecom, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C8ED38817030CF19BE6EE39708627BA

File PE Metadata
Compilation timestamp:
6/17/2014 10:35:36 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:UxpJMyVWJ0q4kfS6wKhmcRf6vEh7+KAFgtp51idtDWEqOWtVr2/NoPH48:opanJ0ZkKIh7mFgfidtDWEn20/No

Entry address:
0x3341

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, F8, 24, 7A, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, 00, 24, 7A, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, 00, 1C, 7A, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 80, 7A, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.5051

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file multiplyroi_tomtom-home.exe has been seen being distributed by the following URL.

Remove multiplyroi_tomtom-home.exe - Powered by Reason Core Security