wajam_install.exe

Wajam

Super Downloads

The file is part of Wajam, a web browser extension that injects social search integration into various search portals such as Google. The application wajam_install.exe by Super Downloads has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.wajam-download.com.
Publisher:
Super Downloads  (signed and verified)

Product:
Wajam

Version:
2.06

MD5:
19f8f6ab6451f743afbafe1e3fdece46

SHA-1:
9f587b0c68b09c2586528a8dc6ceafc7a9c6a2ca

SHA-256:
de9d5e2f4d4a22fcdfe70ad950441ad39984ffa18c9d3dd2353920ffdc5713ae

Scanner detections:
18 / 68

Status:
Adware

Analysis date:
4/26/2024 6:24:29 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Agent.NTM
1142

AVG
AdInject.Wajam
2014.0.3620

Bitdefender
Adware.Agent.NTM
1.0.20.1765

Boost by Reason
Optional.SuperDownloads.N
188163

Dr.Web
Adware.Searcher.2467
9.0.1.03

Emsisoft Anti-Malware
Adware.Agent.NTM
8.13.12.19.07

ESET NOD32
Win32/Wajam
7.9244

Fortinet FortiGate
Riskware/Wajam
12/19/2013

F-Secure
Adware.Agent.NTM
11.2013-19-12_5

G Data
Win32.Application.Wajam
13.12.22

K7 AntiVirus
Trojan
13.174.10720

Malwarebytes
PUP.Optional.Wajam
v2013.12.19.07

McAfee
Artemis!19F8F6AB6451
5600.7276

MicroWorld eScan
Adware.Agent.NTM
14.0.0.1059

Panda Antivirus
Suspicious file
13.12.19.07

Reason Heuristics
PUP.SuperDownloads.N
14.3.2.13

Trend Micro House Call
TROJ_GEN.F47V1213
7.2.353

VIPRE Antivirus
Wajam
25042

File size:
919.7 KB (941,728 bytes)

Copyright:
© Wajam. All right reserved.

Trademarks:
Wajam – Great minds search alike.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\wajam_install.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/11/2013 10:00:00 PM

Valid to:
12/11/2016 9:59:59 PM

Subject:
CN=Super Downloads, O=Super Downloads, STREET="4115, boul. St-Laurent", L=Montreal, S=Quebec, PostalCode=H2W 1Y7, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EDE829ED1E6AB7C7A9D6279BB970B503

File PE Metadata
Compilation timestamp:
12/5/2009 8:53:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:nj1f+Lima3zCqZU6Tr8qVHcI8kk26U2/TJlMX:n8Ja3moU6f78ImdFQX

Entry address:
0x36A0

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 88, A7, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 80, 40, 00, 53, FF, 15, 88, 82, 40, 00, 6A, 08, A3, B8, 63, 42, 00, E8, EE, 2E, 00, 00, A3, 04, 63, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, B0, 0C, 42, 00, FF, 15, 58, 81, 40, 00, 68, 10, A8, 40, 00, 68, 00, 5B, 42, 00, E8, F4, 29, 00, 00, FF, 15, B0, 80, 40, 00, BF, 00, C0, 42, 00, 50, 57, E8, E2, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24.5 KB (25,088 bytes)

The file wajam_install.exe has been seen being distributed by the following URL.

Remove wajam_install.exe - Powered by Reason Core Security