uninstall82378137.exe

YourFile Downloader

Via Advertising Group Limited

This is the Via Advertising bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application uninstall82378137.exe by Via Advertising Group Limited has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the YourFile Downloader installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from dn.yourfiledownloader.com and multiple other hosts.
Publisher:
http://yourfiledownloader.com  (signed by Via Advertising Group Limited)

Product:
YourFile Downloader

Version:
1, 0, 0, 293

MD5:
3eac2ce2f480b2551e3f85c9c97ea3ef

SHA-1:
358480f4e7fedc8e507521ed2b5bdee58d376225

SHA-256:
86862eb97f40d666c50e0baa29f996ed996ad24f2cb60ae53042962e3b59ea60

Scanner detections:
15 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/20/2024 1:46:25 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Downloader-UGW [PUP]
2014.9-141217

AVG
Skodna.Bundle_r.E
2014.0.3614

Dr.Web
Adware.Downware.1140
9.0.1.0351

Emsisoft Anti-Malware
Trojan.Win32.YourFileDownloader.AMN
8.13.12.25.04

ESET NOD32
Win32/YourFileDownloader (variant)
7.8099

Fortinet FortiGate
W32/SPNR.08BP13!tr
12/17/2014

herdProtect (fuzzy)
2014.1.5.14

K7 AntiVirus
Unwanted-Program
13.176.11302

Malwarebytes
PUP.Optional.YourFileDownloader
v2014.12.17.01

McAfee
Artemis!EA305050178D
5600.6914

Reason Heuristics
PUP.ViaAdvertisingGroupLimited.R
14.8.15.17

Sophos
Generic PUA CN
4.98

Trend Micro House Call
TROJ_GEN.F47V0218
7.2.359

Trend Micro
TROJ_SPNR.08BP13
10.465.17

VIPRE Antivirus
Via Advertising
15944

File size:
4.6 MB (4,850,096 bytes)

Product version:
1.0.0

Copyright:
Copyright http://yourfiledownloader.com (C) 2012

Original file name:
YourFile.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
YourFile Downloader

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\uninstall82378137.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/30/2012 2:00:00 AM

Valid to:
5/1/2013 1:59:59 AM

Subject:
CN=Via Advertising Group Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Via Advertising Group Limited, L=Nicosia, S=Nicosia, C=CY

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
54119944225483D152EE7DAA2475480B

File PE Metadata
Compilation timestamp:
2/11/2013 9:22:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:bVlZcS44lJH2PGb1GFIJ4jfbYLXn/CyRGNEKcrXfQV7US2acLLb:jZcS44lJegzJ4jTYLXn/PytcDQeoE

Entry address:
0xC883

Entry point:
E8, 0D, 66, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A0, 01, 00, 00, 81, F9, 80, 00, 00, 00, 72, 1C, 83, 3D, 84, 87, 42, 00, 00, 74, 13, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 05, E9, 47, 08, 00, 00, F7, C7, 03, 00, 00, 00, 75, 14, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 29, F3, A5, FF, 24, 95, 00, CA, 40, 00, 8B, C7, BA, 03, 00, 00, 00, 83, E9, 04, 72, 0C, 83, E0, 03, 03, C8, FF, 24...
 
[+]

Entropy:
7.8724  (probably packed)

Code size:
103 KB (105,472 bytes)

The file uninstall82378137.exe has been seen being distributed by the following 11 URLs.

http://dn.yourfiledownloader.com/j5GMUGXJ6WtpxO0SKuy5Ji7voShgufkEcOSUKH2xwQNxvMV/.../ymjJDvMxUHu7TFEeCjgZfgMBeCNAnB03RNER0wjFDdsc5TQ==

http://dn.yourfiledownloader.com/j5G2Q2fZp1ljxqofbcq LHjZ9SZ1pbc/.../aeNk w0Gga6tcQW76CCluExFgO0tsbSdUwQAjePUZ7wz5I

Remove uninstall82378137.exe - Powered by Reason Core Security