AppWork GmbH

Publisher Information

AppWork GmbH is a software publisher located in Fuerth, Bayern in Germany*. The publisher primarily developes software that can be classified as adware. Thre are 4 additional code signing certificates issued to this publisher.
Remove AppWork GmbH Malware - Powered by Reason Core Security
Authority:
GlobalSign nv-sa

Valid from:
1/31/2014 3:51:29 PM

Valid to:
4/1/2015 4:00:41 PM

Subject:
E=e-mail@appwork.org, CN=AppWork GmbH, O=AppWork GmbH, L=Fuerth, S=Bayern, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11218c489dbd3bc8af35cdb519ba450dc59a

Scanner detections:
Detections  (98% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.AppWorkGmbH.T, PUP.Installer.AppWorkGmbH.V, PUP.Installer.AppWorkGmbH.Z, PUP.Installer.AppWorkGmbH.M, PUP.Installer.AppWorkGmbH.P, PUP.AppWorkGmbH.M, PUP.AppWorkGmbH.S, PUP.Installer.AppWorkGmbH.W, PUP.Installer.AppWorkGmbH.S, PUP.Bundler.installCore, PUP.installCore (M), PUP.installCore.Installer (M)
100.00%

AVG
Generic, Generic_r
38.78%

ESET NOD32
Win32/InstallCore.PO (variant), Win32/InstallCore.LN (variant), Win32/OpenCandy (variant), Win32/InstallCore.PX (variant)
18.37%

Avira AntiVirus
ADWARE/InstallCore.Gen9, TR/Crypt.XPACK.Gen
16.33%

Dr.Web
Trojan.Packed.26937, Adware.Downware.5119
14.29%

McAfee
Artemis!7686C2508575, Artemis!2D06F7292B97, Artemis!6EC3C6C18726, Artemis!7281EE288886, Artemis!5FD485E8846D, Artemis!956B4C87FAE7, Artemis!439C35471D45
14.29%

Sophos
Install Core, PUA 'Install Core'
12.24%

Trend Micro House Call
Suspicious_GEN.F47V0720, Suspicious_GEN.F47V0718, Suspicious_GEN.F47V0812, Suspicious_GEN.F47V0628, Suspicious_GEN.F47V0711
12.24%

McAfee Web Gateway
Artemis!7686C2508575, Artemis!2D06F7292B97, Artemis!6EC3C6C18726, Artemis!7281EE288886, Artemis!439C35471D45
12.24%

VIPRE Antivirus
Trojan.Win32.Generic, DownloadGuide
10.20%

1 / 68      (PUP)
JD09Setup_CV.exe (JDownloader by AppWork GmbH)  (98a1a962614976b984d7e30157c9e450)

1 / 68      (PUP)
03e1cc3e_stp.exe (JDownloader by AppWork GmbH)  (9e39be12ee798dd60ea235a86e8f22c6)

1 / 68      (PUP)
7154f2b0_stp.exe (JDownloader by AppWork GmbH)  (7bc33b1e952db8572b202a61dde24e9c)

1 / 68      (PUP)
0d43df0c_stp.exe (JDownloader by AppWork GmbH)  (a53e34e5f1c318d3738827ce2ab8a031)

1 / 68      (PUP)

1 / 68      (PUP)
2005d62e_stp.exe (JDownloader by AppWork GmbH)  (a7a68e45b0a8084f16bf046bc737b3cb)

1 / 68      (PUP)
441742286_stp.exe  (e42fd3fcc64aa52fe07070fa4384aab5)

2 / 68      (PUP)

8 / 68      (PUP)

1 / 68      (PUP)
642a6f7f_stp.exe (JDownloader by AppWork GmbH)  (de60739419b025e3211e91f45bfebbba)

11 / 68    (PUP)
130524830211551876.exe (My Program)  (4e9c62ae3e42e22874385224561bec06)

1 / 68      (PUP)
17071df9_stp.exe (JDownloader by AppWork GmbH)  (f27e090b8f78fd3eb2032e6c2304c243)

4 / 68      (PUP)

3 / 68      (PUP)
f_000234  (71632f12b79c2237d6948d7184775e45)

5 / 68      (PUP)
installer_jdownloader_two.exe  (bedd688fb9a6012a620cf1f66d1ddc76)

6 / 68      (PUP)
webinstaller.exe (JDownloader2 (BETA) by AppWork GmbH)  (956b4c87fae78aced3687b1479f97447)

5 / 68      (PUP)
webinstaller_jd1_c.exe (JDownloader by AppWork GmbH)  (5fd485e8846debb64b61df360738777a)

13 / 68    (PUP)
jdsetup130548193888059476.exe  (7281ee288886dd5483765b7183d458d5)

14 / 68    (PUP)
130524321161729689.exe (My Program)  (6ec3c6c1872686d21b335152f4582a4b)

2 / 68      (PUP)
webinstaller.exe (JDownloader 0.9581 by AppWork GmbH)  (376f12fe3f5215ee1a4b42ba19f12bb6)

3 / 68      (PUP)
jdsetup130524323853461522.exe (My Program)  (d7b2e6a3a3a722f880663bcfe621d76e)

2 / 68      (PUP)
webinstaller.exe (JDownloader 0.9581 by AppWork GmbH)  (ffb2fb95f650a33bfcb89fd29c14a64a)

6 / 68      (PUP)
130523287377435248.exe (My Program)  (67d48a5fe63d8182989e6060520151be)

1 / 68      (PUP)

1 / 68      (PUP)
jdownloader updater.exe  (0ddf73ab16eeaa8d445ffdaed4057404)

1 / 68      (PUP)

1 / 68      (PUP)
jdownloader updater.exe  (d07f0d41d4261377b877c541ea34addd)

1 / 68      (PUP)
jdownloader09setup_win.exe (JDownloader by AppWork GmbH)  (446e8b8cdd2e94812229d926be5772eb)

3 / 68      (PUP)

1 / 68      (PUP)

 
Latest 30 of 140 files

Downloads URLs for files signed by AppWork GmbH.

1 / 68      (PUP)

1 / 68      (PUP)

6 / 68      (PUP)
http://installer.jdownloader.org/WebInstallerJD2_c.exe  (956b4c87fae78aced3687b1479f97447)

3 / 68      (PUP)

5 / 68      (PUP)
http://jdownloader.org/.../dl.php?v=2  (installer_jdownloader_two.exe)

2 / 68      (PUP)
http://installer.jdownloader.org/.../WebInstallerJD1.exe  (ffb2fb95f650a33bfcb89fd29c14a64a)

2 / 68      (PUP)
http://installer.jdownloader.org/WebInstaller.exe  (ffb2fb95f650a33bfcb89fd29c14a64a)

2 / 68      (PUP)
http://installer.jdownloader.org/WebInstaller.exe  (376f12fe3f5215ee1a4b42ba19f12bb6)

2 / 68      (PUP)
http://installer.jdownloader.org/.../WebInstallerJD1.exe  (ffb2fb95f650a33bfcb89fd29c14a64a)

The following websites host and distribute files published by AppWork GmbH.

The certificates below are also signed by AppWork GmbH.

5CA15B949EC0CBCECEB7C57981B033A8  (Jan 28, 2015 to Jan 29, 2016)

4C87501159A97E0FA43CF04A705381FC  (Jan 28, 2015 to Jan 28, 2016)

0091626FD168636EDD78A174E8B75DAC  (Aug 15, 2014 to Aug 16, 2015)

0100000000012E71E7355C  (Mar 01, 2011 to Mar 01, 2014)

The following publishers (by Authenticode signature organization name) are related.

Remove AppWork GmbH Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to AppWork GmbH by GlobalSign nv-sa on January 31, 2014 with the serial number '11218c489dbd3bc8af35cdb519ba450dc59a'.