walppapers igli5.com.exe

SystemNode

Maxiget Limited

This is a bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application walppapers igli5.com.exe by Maxiget Limited has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the New IT Desktop Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
SwapSystem  (signed by Maxiget Limited)

Product:
SystemNode

Description:
SystemComponent

Version:
4, 0, 32, 0

MD5:
0e4e453c2e7345b3d1aff27efff6475e

SHA-1:
f841ca725689232e3f5a2718960d12edc3f1fba1

SHA-256:
6cf310db2a32d1587e930771e93ec6422428f69839aa337ed95653f61305aff3

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This is a modified installer version of the software and bundles additional offers including adware.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 5:49:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Strictor.69555
795

Agnitum Outpost
PUA.4Shared
7.1.1

Avira AntiVirus
APPL/Downloader.Gen8
7.11.189.70

AVG
Generic
2015.0.3273

Bitdefender
Gen:Variant.Strictor.69555
1.0.20.1675

Dr.Web
Adware.Downware.2538
9.0.1.0335

Emsisoft Anti-Malware
Gen:Variant.Strictor.69555
8.14.12.01.09

ESET NOD32
Win32/4Shared.AB potentially unwanted application
7.0.302.0

F-Prot
W32/A-2deba07d
v6.4.7.1.166

F-Secure
Gen:Variant.Strictor.69555
11.2014-01-12_2

G Data
Gen:Variant.Strictor.69555
14.12.24

K7 AntiVirus
Unwanted-Program
13.186.14174

MicroWorld eScan
Gen:Variant.Strictor.69555
15.0.0.1005

NANO AntiVirus
Riskware.Win32.Downware.djadfp
0.28.6.63726

Panda Antivirus
Trj/Genetic.gen
14.11.28.02

Reason Heuristics
PUP.MaxigetLimited.T
14.11.28.2

Vba32 AntiVirus
TrojanDropper.Agent
3.12.26.3

VIPRE Antivirus
Threat.4150696
35224

Zillya! Antivirus
Backdoor.Pigeon.Win32.1003
2.0.0.1995

File size:
676.7 KB (692,928 bytes)

Product version:
4, 0, 32, 0

Copyright:
2014

Trademarks:
SmallTrade Inc.

Original file name:
0008.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
New IT Desktop Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\walppapers igli5.com.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
11/4/2014 11:59:17 AM

Valid to:
8/15/2016 8:41:32 AM

Subject:
CN=Maxiget Limited, O=Maxiget Limited, L=Limassol, S=Cyprus, C=CY

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B6558A31AA7EB

File PE Metadata
Compilation timestamp:
11/25/2014 6:24:31 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:aBWBkphGhpAwJL6iu1tGvmfJks5e88oes7Ji1E5BBuP7pt3o:NkphqyGBs5elA7JJM7pNo

Entry address:
0x49331

Entry point:
E8, DC, BE, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 14, A1, D8, 7E, 47, 00, 33, C5, 89, 45, FC, 53, 56, 33, DB, 57, 8B, F1, 39, 1D, 9C, D4, 4A, 00, 75, 38, 53, 53, 33, FF, 47, 57, 68, 60, B6, 46, 00, 68, 00, 01, 00, 00, 53, FF, 15, AC, 31, 46, 00, 85, C0, 74, 08, 89, 3D, 9C, D4, 4A, 00, EB, 15, FF, 15, F8, 30, 46, 00, 83, F8, 78, 75, 0A, C7, 05, 9C, D4, 4A, 00, 02, 00, 00, 00, 39, 5D, 14, 7E, 22, 8B, 4D, 14, 8B, 45, 10, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, 45, 14, 2B, C1...
 
[+]

Code size:
391 KB (400,384 bytes)

Remove walppapers igli5.com.exe - Powered by Reason Core Security