adlsoft_uncompressor.exe

ADLSoft

The application adlsoft_uncompressor.exe by ADLSoft has been detected as adware by 15 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from s3.amazonaws.com.
Publisher:
ADLSoft  (signed and verified)

MD5:
42b1e5c3a0624350c34d2e856e902b75

SHA-1:
2f18d4a14d6b5c66757c8854cda22dd1c3b0b042

SHA-256:
6bcbe714760acef67f48f482a3c4cf764e68e3a1d3cb2b1fe209f53127590481

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Uses the InstallCore download and install manager which may bundle various potentially unwanted software offers during setup.

Analysis date:
4/19/2024 7:27:33 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2013.10.10

Avira AntiVirus
7.11.106.210

Clam AntiVirus
W32.Adware.InstallCore
0.98/18155

Comodo Security
UnclassifiedMalware
17077

Dr.Web
Adware.InstallCore.40
9.0.1.0126

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.62453
8.14.05.06.06

ESET NOD32
Win32/InstallCore (variant)
8.8896

F-Prot
W32/InstallCore.C.gen
v6.4.7.1.166

G Data
Gen:Variant.Adware.Graftor.62453
14.5.22

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.0.127

Malwarebytes
PUP.Adware.InstallCore
v2014.05.06.06

McAfee
Artemis!42B1E5C3A062
5600.7139

Reason Heuristics
PUP.ADLSoft.U
14.8.8.3

SUPERAntiSpyware
Adware.InstallCore
10622

Vba32 AntiVirus
Adware.InstallCore.gen
3.12.24.3

File size:
1 MB (1,093,640 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adlsoft_uncompressor.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/22/2011 2:00:00 AM

Valid to:
7/26/2012 1:59:59 AM

Subject:
CN=ADLSoft, O=ADLSoft, L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
522DE3F48188350D9BEBAD2434E15998

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:ipHNHV6e6u2CzqYPEgz1fDg2kJ8pWzB05dtK4KdNqzI1TAEq1hYeEZK4nedcT7yf:gtpzQzdEzIU6T+f

Entry address:
0xC1ECC

Entry point:
55, 8B, EC, 83, C4, F0, B8, 19, 46, 4F, 00, E8, 64, D9, FF, FF, 61, 60, FE, AD, 2E, F5, BB, D8, 94, 75, 48, EA, 40, 0D, 8C, F8, 33, 61, 64, 56, E1, BC, 03, A9, A0, D9, 73, AB, 4C, F8, 4A, CC, 63, 00, D1, 2F, F7, D4, 33, C6, 1A, 47, 7B, 83, C2, 26, 76, D7, 46, 5F, B4, 0A, DF, 40, 4A, 0C, E4, 39, 09, DC, 9A, BA, 4B, AF, DA, 10, 98, 4A, E6, 47, AD, 62, 2B, 8F, B6, ED, C1, 9C, C5, AC, 01, FC, D5, 54, 64, 6A, DC, 31, 8D, 7D, C5, 29, 45, 62, 54, 61, A9, 5F, 41, 00, EA, 51, 1F, CD, 56, 7C, CB, A7, 88, 44, 84, 03...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
786.5 KB (805,376 bytes)

The file adlsoft_uncompressor.exe has been seen being distributed by the following URL.

Remove adlsoft_uncompressor.exe - Powered by Reason Core Security