update.exe

Wajam Internet Technologies Inc

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application update.exe by Wajam Internet Technologies Inc has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Wajam which is a potentially unwanted software program.
Remove update.exe - Powered by Reason Core Security
Publisher:
Wajam Internet Technologies Inc  (signed and verified)

MD5:
3068b52cd395860cab92b368f4a0bcca

SHA-1:
5cc07efb1f251ba8e5c542c750c97837c0782fab

SHA-256:
1100d7ac5aba5cfef09d248064ae46d8534385720514c95cc3328f11e5632b95

Scanner detections:
24 / 68

Status:
Adware

Analysis date:
12/8/2016 3:18:53 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInject.Wajam
2015.0.3447

Bkav FE
W32.Clod6f1.Trojan
1.3.0.4959

Dr.Web
Adware.Searcher.2467
9.0.1.0161

G Data
Win32.Application.Wajam
14.6.24

Reason Heuristics
PUP.WajamInternetTechnologies.G
14.8.7.21

VIPRE Antivirus
Wajam
29884

Remove update.exe - Powered by Reason Core Security
File size:
97.5 KB (99,800 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\wajam\updater\update.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/9/2013 4:30:00 AM

Valid to:
7/10/2018 4:29:59 AM

Subject:
CN=Wajam Internet Technologies Inc, O=Wajam Internet Technologies Inc, STREET=4115 Saint-Laurent Blvd, L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008DAB5910F20F42BD7B16C6EBC90BB13C

File PE Metadata
Compilation timestamp:
12/6/2009 2:23:24 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:LCuFP2lXIHDgXJFpCuHMOL0vtyKYJih4gDb+7j8k:L1834uHMg0QKQM40+7B

Entry address:
0x355E

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B8, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, 98, 10, 43, 00, E8, D6, 2E, 00, 00, A3, E4, 0F, 43, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, E8, A7, 42, 00, FF, 15, 58, 81, 40, 00, 68, AC, A7, 40, 00, 68, E0, 07, 43, 00, E8, DC, 29, 00, 00, FF, 15, AC, 80, 40, 00, BF, 00, 70, 43, 00, 50, 57, E8, CA, 29, 00, 00...
 
[+]

Entropy:
7.6380

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file update.exe has been discovered within the following programs.

Wajam  by Wajam
Wajam is a search-enhancement product, but it does not change homepage or search. This product shows display and/or text ads into third-party websites which may alter normal web page layouts.
www.wajam.com
73% remove it
 
Powered by Should I Remove It?

Remove update.exe - Powered by Reason Core Security