PUP.EZDownloader

Threat Scorecard

Popularity Rank: 13,283
Threat Level: 10 % (Normal)
Infected Computers: 11,543
First Seen: November 18, 2013
Last Seen: January 15, 2026
OS(es) Affected: Windows

File System Details

PUP.EZDownloader may create the following file(s):
# File Name MD5 Detections
1. EZDownloader.exe.vir 644d6bd82b1bfbd4cfb44288bbd518e5 1,619
2. ezdownloader[1].exe 71f784969d24240764d5e5d752d55a41 879
3. ezdownloader.exe 292b53b745e3fc4af79924a3c11fcff0 2
4. Download.exe ebd73e1ddd381cccf5e2b2e2a8398349 2

Registry Details

PUP.EZDownloader may create the following registry entry or registry entries:
File name without path
EZDownloader.lnk
http_lp.ezdownloadpro.info_0.localstorage
http_lp.ezdownloadpro.info_0.localstorage-journal
Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader\EZDownloader.lnk
Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EZDownloader\EZDownloader.lnk
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1

Directories

PUP.EZDownloader may create the following directory or directories:

%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\EZDownloader
%APPDATA%\EZDownloader
%PROGRAMFILES%\EZDownloader
%PROGRAMFILES(X86)%\EZDownloader

Analysis Report

General information

Family Name: PUP.EZDownloader
Signature status: Self Signed

Known Samples

MD5: 6ef6a6a5bc8f14cc305f7a8f6ac06755
SHA1: 100a8e1c4a1e0e937be08d54c425c06c3f58cfd4
SHA256: E9F9904B5C7BBA264FF62A51B922E4687F1AA4B2D9E8A94F7DBC6FF559E42187
File Size: 4.63 MB, 4632064 bytes
MD5: 96caf474c8f98c31a4d08eb241cc6a5f
SHA1: 9822b96d5b06038de303544e1e6f1a42541a16ba
SHA256: 5D5457C47ED47AC466C977B2F3E64C6F97760286AC0124D510217C18034BD3A1
File Size: 849.94 KB, 849944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments http://izloader.com/
Company Name http://izloader.com/
File Description EasyDownloads Application
File Version 1, 0, 0, 1
Internal Name EasyDownloads
Legal Copyright Copyright (C) http://izloader.com/ 2010.All rights reserved.
Original Filename EasyDownloads.exe
Product Name EasyDownloads Application
Product Version 1, 0, 0, 1

Digital Signatures

Signer Root Status
Safe Decision, Inc Safe Decision, Inc Self Signed
Safe Decision, Inc UTN-USERFirst-Object Root Not Trusted

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 0
Whitelisted Blocks: 1
Unknown Blocks: 9

Visual Map

? ? ? ? 0 ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\htmlayout.dll Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...