Sunday, September 21, 2014

Malicious sponsorware reportedly found on jdownloader.org





# 1 badware can be downloaded at fileextractorapp[dot]com/file-extractor/gb/oc/?adnm=36846744619&i=s&grid=&lg=en&cc=US&clg=en&c=1&d=0&cid=_975366271&kw=zip&mt=&mn=jdownloader.org&ct=&nt=D&expr=&ap=none&dv=c&&agid=_97191062311&gclid=CMSZ0KHu88ACFaVZ7AodHloA8w

  1. Application name: Free File-Extractor
  2. Setup file MD5:1f0b5f9aba6a8b68b7903ea6fbf5e032
  3.  Publisher: PersonalCleaner
  4. Associated junkware include Norton Security Scan, Dealply and other un-related BHOs, according to this "Uninstall" page @ fileextractorapp[dot]com/uninstall
  5. The site claims that "This product is totally free and offers the user additional bundle products that may include advertisement"
  6. VT says... for more details, hit this link.
  7. Finally, I got a known application File Extractor from Tweaks (site: file-extractor[dot]com/ but nothing to view now).
  8. After the "shorten" install process, I saw an ad for the download for Driver Support.

Malware sample #2 could be downloaded from my-downloads[dot]net/download/?pi=jdownloader.org&gclid=CKr-z7Dx88ACFWwQ7AodPzAA0A. Take a closer look at the (potential) junk infection:


  1. Filename: manualdownload.exe
  2. MD5: ba83a01cbd09206d70a0d5b7652cae24
  3. Publisher: InstallX
  4. VT file is here.
  5. Crapware include: AstroArcade, Norton Internet Security, ArcadeParlor, ResutlsBay (clone of SerialTrunc), MyPC Backup, PC Optimizer Pro, and PC Speed UP.


ENJOY YOUR DOWNLOAD(S)?!!!

No comments:

Post a Comment