Gridinsoft Logo
File Icon

KeyMaker Bandicam[pWZuJAaYqa].exe PUP DownStudio Analysis

Technical Analysis

File Name KeyMaker Bandicam[pWZuJAaYqa].exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Scanner Version 1.0.176.174
Database Version 2024-05-20 15:00:21 UTC

PUP.Win32.DownStudio.mz!c

Malware family: DownStudio

N/A
Detection Rate
532,312
File Size (bytes)
2024-05-20
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
3e0514bf298c9f5f03bd570799bb5da7
SHA1
9b5297aa7cefd32fccf0c64292068586cc74c735
SHA256
a8dbc3aee62133e5735442327351d27a316f5d4bc529973e0120d2e6a500abf7
SHA512
fb162d98bbf2945291ae51b0251a9e45f0c912bbf8dda867c54ee1a3f4614651cf68f77e98f4ebafcdb273e6e94b124bf3626772164f85f78d16ecf94d307ae3
ImpHash
c9436c0763c8826fdef00d2d8ed39d7c

PE Analysis

Basic Information

Icon
Hash: 3d3e538a4fda132994634c0c5960a012
Fuzzy: 8ddde8a305c798f73cfc7b053d57e6a5
dHash: 8c3af8b8e8e43a8c
Image Base 0x00400000
Entry Point 0x0040338f
Compilation Time 2022-09-20 09:43:28
Checksum 0x0008d9e4 (Actual: 0x0008d9e4)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
Digital Signature Chain verification from 1.3.6.1.4.1.311.60.2.1.3=UA, 2.5.4.15=Private Organization, CN=GRAND MEDYA\, TOV, 2.5.4.5=39638734, O=GRAND MEDYA\, TOV, L=Odesa, C=UA (serial:1134515227303628590318727680469764066, sha1:2f0ffe2afbff5c9d40bd8b6832997a322df7fcb0) failed: Unable to build a validation path for the certificate "Incorporation Country: UA; Business Category: Private Organization; Common Name: GRAND MEDYA, TOV; Serial Number: 39638734; Organization: GRAND MEDYA, TOV; Locality: Odesa; Country: UA" - no issuer matching "Common Name: SSL.com EV Code Signing Intermediate CA RSA R3, Organization: SSL Corp, Locality: Houston, State/Province: Texas, Country: US" was found
Imports 7 libraries
ADVAPI32, SHELL32, ole32, COMCTL32, USER32, GDI32, KERNEL32
Exports 0 functions
Resources 17 Resources
Sections 5 Sections

Version Information

CompanyName Download Studio Project
FileDescription DS Setup
FileVersion 1.20.0.0
LegalCopyright 2023 (c) Download Studio Project
ProductName DS Setup
ProductVersion 1.20.0.0 (rv126)
Translation 0x04b0 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 24,032 bytes 24,064 bytes 6.46 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 1840977CA4E7DF4C66C64077562CE871
.rdata 0x00007000 6,068 bytes 6,144 bytes 5.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ F7FDDD0110CEBF8CF7A0568622AB6A17
.data 0x00009000 455,424 bytes 512 bytes 2.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 737E95A682DE4A9BFE0EA69FB3755941
.gdata 0x00079000 2,113,536 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x0027d000 123,592 bytes 123,904 bytes 5.03 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FDDED3EDE6C45037338ED57802A43E9F

Resource Analysis

Total Resources: 17 (122,618 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 118,636 bytes
96.8%
RT_DIALOG 7 1,978 bytes
1.6%
RT_GROUP_ICON 1 104 bytes
0.1%
RT_VERSION 1 640 bytes
0.5%
RT_MANIFEST 1 1,260 bytes
1%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

Chain verification from 1.3.6.1.4.1.311.60.2.1.3=UA, 2.5.4.15=Private Organization, CN=GRAND MEDYA\, TOV, 2.5.4.5=39638734, O=GRAND MEDYA\, TOV, L=Odesa, C=UA (serial:1134515227303628590318727680469764066, sha1:2f0ffe2afbff5c9d40bd8b6832997a322df7fcb0) failed: Unable to build a validation path for the certificate "Incorporation Country: UA; Business Category: Private Organization; Common Name: GRAND MEDYA, TOV; Serial Number: 39638734; Organization: GRAND MEDYA, TOV; Locality: Odesa; Country: UA" - no issuer matching "Common Name: SSL.com EV Code Signing Intermediate CA RSA R3, Organization: SSL Corp, Locality: Houston, State/Province: Texas, Country: US" was found

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

PUP.Win32.DownStudio.mz!c Removal

Gridinsoft has the capability to identify and eliminate PUP.Win32.DownStudio.mz!c without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware