AppWork GmbH

Publisher Information

AppWork GmbH is a software publisher located in Fürth, Bavaria in Germany*. The publisher primarily developes software that can be classified as adware. Thre are 4 additional code signing certificates issued to this publisher.
Remove AppWork GmbH Malware - Powered by Reason Core Security
Authority:
GlobalSign nv-sa

Valid from:
3/1/2011 3:00:48 PM

Valid to:
3/1/2014 3:00:41 PM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fürth, S=Bavaria, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012e71e7355c

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.AppWorkGmbH.T, PUP.Installer.AppWorkGmbH.U, PUP.Installer.AppWorkGmbH.Q, PUP.Installer.AppWorkGmbH.X, PUP.Installer.AppWorkGmbH.CC, PUP.Installer.AppWorkGmbH.R, PUP.Installer.AppWorkGmbH.W, PUP.Installer.AppWorkGmbH.L, PUP.Installer.AppWorkGmbH.V, PUP.AppWorkGmbH.K, PUP.Installer.AppWorkGmbH.J, PUP.Installer.installCore, PUP.Bundler.installCore, PUP.installCore.Installer, PUP.installCore (M), PUP.installCore.Installer (M)
100.00%

Trend Micro House Call
TROJ_FAKEAV.BMC, TROJ_GEN.F47V1213, TROJ_GEN.F47V0815, TROJ_GEN.F47V1217, TROJ_GEN.RCBH1KJ, TROJ_GEN.FCBCBL5, TROJ_GEN.R06H1GT, HV_ZYX_BK083333.TOMC
30.00%

CMC Antivirus
Virus.Win32.Xpaj.1!O
18.00%

ESET NOD32
Win32/InstallCore.BY (variant), Win32/InstallCore.AT (variant), Win32/InstallCore.CF (variant), Win32/InstallCore.BA (variant)
14.00%

Dr.Web
Trojan.Packed.24399, Adware.InstallCore.64, Adware.InstallCore.45, Adware.InstallCore.76, Adware.InstallCore.55
12.00%

Avira AntiVirus
Adware/InstallCore.IC, ADWARE/InstallCore.Gen
12.00%

Vba32 AntiVirus
Malware-Cryptor.InstallCore.9, suspected of Trojan.Downloader.gen.h, BScope.Malware-Cryptor.MTA.01650, BScope.Malware-Cryptor.InstallCore.2691
8.00%

The Hacker
Trojan/FraudPack.cfpz, Trojan/Downloader.Agent.cbn
4.00%

Trend Micro
TROJ_FAKEAV.BMC, TROJ_GEN.FCBCBL5
4.00%

Microsoft Security Essentials
SoftwareBundler:Win32/DealPly
4.00%

1 / 68      (PUP)
icreinstall_jdownloadersetup_ch3.exe  (f95d23d977ab3af51d9e32d1847d7a0c)

1 / 68      (PUP)
icreinstall_jdownloadersetup.exe  (e1e7db2a5aa86880177b4c11735985be)

1 / 68      (PUP)
JDownloader2Setup.exe (JDownloader by AppWork GmbH)  (d54fc36c51518344687d8088c3ef4df8)

1 / 68      (PUP)
jdownloadersetup_ch2.exe  (e183ac27748fe8a1df884e7892d49362)

1 / 68      (PUP)
jdownloadersetup.exe  (2f62d3e9ab0c0fd4b7a0901e570371d6)

1 / 68      (PUP)
jdownloadersetup_ch3.exe  (e612fd4d04e7688d01ba5d621192039a)

1 / 68      (PUP)
jdownloaderportable.exe (JDownloader 0.9 by AppWork GmbH)  (bf732516cc668c05f891ff31d7153c28)

1 / 68      (PUP)
jdownloadersetup.exe  (08262a08940a34068acab0edf96d5464)

1 / 68      (PUP)
JDLauncher.exe (JDownloader by AppWork GmbH)  (adcae273b166d29fbefcb86f0032bd18)

1 / 68      (PUP)
jdownloadersetup_3ic.exe  (43202d481bcd3e595bc3b6e2b303f7a8)

1 / 68      (PUP)
jdownloadersetup_ch5.exe  (64ddaabacdd54115905d782b8b9008c8)

1 / 68      (PUP)
jdownloadersetup_3ic.exe  (8e80fc5ad2de1b27ba56b6d183425fd9)

1 / 68      (PUP)
jdownloaderportable.exe (JDownloader 0.9 by AppWork GmbH)  (9bd18aa8700dbaa37a60b3d556835fa4)

1 / 68      (PUP)
jdownloadersetup_ch2.exe  (f908554e6dcb91dc1edb3c09788a7b70)

1 / 68      (PUP)
file0.exe (JDownloader by AppWork GmbH)  (8399ba37c6f6b6cfb06a42ba8cd57a8e)

3 / 68      (PUP)
JDownloaderSetup.exe (JDownloader by AppWork GmbH)  (017d5bd693a926770c77d8ba57904a8a)

1 / 68      (PUP)
jdownloadersetup.exe (JDownloader by AppWork GmbH)  (557b2677ba2e95b4f630fe0a8c2653fb)

3 / 68      (PUP)
JDownloaderSetup.exe (JDownloader by AppWork GmbH)  (b7a1de38bca95da11ff0bacec53311ab)

3 / 68      (PUP)
JDownloaderSetup.exe (JDownloader by AppWork GmbH)  (f8297986a6b68d66fefdcf521434e20a)

1 / 68      (PUP)
jdownloader (thefredrm).exe (JDownloader by AppWork GmbH)  (d505ba3ff79dcc94c19f1a1b6612d0de)

1 / 68      (PUP)
jdownloader2setup.exe (JDownloader by AppWork GmbH)  (d177f11c8eab9de70550d26e1071461d)

1 / 68      (PUP)
jdownloaderportable.exe (JDownloader 0.9 by AppWork GmbH)  (1c732c9c4aa5d56ee6cdf31804ce6fd6)

6 / 68      (PUP)
jdownloadersetup_ch4.exe  (7af4252e64d4b201c60b4b3c41a1c1af)

1 / 68      (PUP)
JDownloaderSetup_IC.exe (JDownloader by AppWork GmbH)  (b3660046ecf302d14f2412965c63c6a1)

3 / 68      (PUP)
JDownloaderSetup.exe (JDownloader by AppWork GmbH)  (437388e3d8dd4fa8a0ec80803161e2a2)

2 / 68      (PUP)

3 / 68      (PUP)
HRAManager.exe (HIGHRESAUDIO Manager by HIGHRESAUDIO UG)  (37de58e383c0bdc7e9684d2a2e5c3c84)

1 / 68      (PUP)
$rd0cptm.exe (JDownloader by AppWork GmbH)  (8d3353dad1dac40cee5afbd4b4fa6ab6)

3 / 68      (PUP)
JDownloaderSetup.exe (JDownloader by AppWork GmbH)  (7612872a3bd972e47331659b1de35d48)

2 / 68      (PUP)

 
Latest 30 of 242 files

Downloads URLs for files signed by AppWork GmbH.

1 / 68      (PUP)

1 / 68      (PUP)

2 / 68      (PUP)
https://mega.nz/temporary/.../2pdknDYQ  (jdownloadersetup_pcworld.exe)

2 / 68      (PUP)

The following websites host and distribute files published by AppWork GmbH.

The certificates below are also signed by AppWork GmbH.

5CA15B949EC0CBCECEB7C57981B033A8  (Jan 28, 2015 to Jan 29, 2016)

4C87501159A97E0FA43CF04A705381FC  (Jan 28, 2015 to Jan 28, 2016)

0091626FD168636EDD78A174E8B75DAC  (Aug 15, 2014 to Aug 16, 2015)

11218C489DBD3BC8AF35CDB519BA450DC59A  (Jan 31, 2014 to Apr 01, 2015)

The following publishers (by Authenticode signature organization name) are related.

Remove AppWork GmbH Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to AppWork GmbH by GlobalSign nv-sa on March 01, 2011 with the serial number '0100000000012e71e7355c'.