pdf unlocker 2.0.3.exe

Download Helper

New IT Limited

This is part of a bundled installer which provides applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application pdf unlocker 2.0.3.exe by New IT Limited has been detected as adware by 20 anti-malware scanners. The file has been seen being downloaded from dc101.4shared.com.
Publisher:
New IT Limited  (signed and verified)

Product:
Download Helper

Version:
1, 1, 0, 0

MD5:
57a5333160c75e54a0b73b805e76c52b

SHA-1:
6b8d2fa129a22475f3ce88cdd95f4b27d98a5ab8

SHA-256:
ce6702ca51c17c08411e99f15f7ac9cda890107bd1e72d70dd675ce4150d4912

Scanner detections:
20 / 68

Status:
Adware

Analysis date:
4/26/2024 9:21:33 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Troj.W32.Gen
2.1.4+

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.125.146

avast!
PUP-gen [PUP]
141214-1

AVG
Adware BundleApp_r.E
2014.0.4189

Clam AntiVirus
Win.Trojan.4shared-5
0.98/19793

Comodo Security
Application.Win32.4Shared.G
17627

Dr.Web
Adware.Downware.2538, Trojan.StartPage.54036
9.0.1.05190

ESET NOD32
Win32/4Shared.C potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/4Shared
12/17/2014

F-Prot
W32/4Shared.G.gen
v6.4.7.1.166

IKARUS anti.virus
APPL
t3scan.2.2.29

K7 AntiVirus
Trojan
13.175.10881

Malwarebytes
PUP.Optional.4Shared
v2014.12.17.02

McAfee
Program.PUP-FIV
16.8.708.2

NANO AntiVirus
Trojan.Win32.StartPage.cxgxgp
0.28.2.60881

Reason Heuristics
PUP.NewITLimited.Q
14.12.17.2

Rising Antivirus
PE:PUF.4Shared!1.9C25
23.00.65.141215

Sophos
PUA '4Share Downloader'
5.09

VIPRE Antivirus
4Shared
25508

File size:
652.9 KB (668,528 bytes)

Product version:
1, 1, 0, 0

Copyright:
Copyright (C) 2013

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pdf unlocker 2.0.3.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
11/16/2012 7:16:05 PM

Valid to:
11/16/2013 5:30:34 PM

Subject:
CN=New IT Limited, O=New IT Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B2A165690BBAA

File PE Metadata
Compilation timestamp:
3/13/2013 10:25:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:i0SlJmmF99W7CQV1POhmmp+ZGnTtmg3Fxx7JvdakTNacsvH:rJw9g7CQjcmi+QnTN3vJxdjpaD

Entry address:
0x9ADD

Entry point:
E8, BB, 45, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 14, E4, 41, 00, 33, C5, 89, 45, FC, F6, 05, E4, E3, 41, 00, 01, 56, 74, 08, 6A, 0A, E8, 4C, 35, 00, 00, 59, E8, 75, 46, 00, 00, 85, C0, 74, 08, 6A, 16, E8, 77, 46, 00, 00, 59, F6, 05, E4, E3, 41, 00, 02, 0F, 84, CA, 00, 00, 00, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC, FD, FF, FF, 66, 8C, 95, F8, FD, FF, FF, 66, 8C, 8D, EC, FD, FF...
 
[+]

Entropy:
6.9964

Code size:
90.5 KB (92,672 bytes)

The file pdf unlocker 2.0.3.exe has been seen being distributed by the following URL.

Remove pdf unlocker 2.0.3.exe - Powered by Reason Core Security