angry-birds-rio.exe

The application angry-birds-rio.exe has been detected as a potentially unwanted program by 22 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
MD5:
b830c1dd5bb692e9409dc97d71234b35

SHA-1:
bbea6d2ffbf633600651dd08b6123dbf19a91a3c

SHA-256:
fb9a76b7f691c948d6bab06dd7df28b885ec38b2cfa64e63367ce7efb83a858e

Scanner detections:
22 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/29/2024 7:17:31 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.333296
1025

Avira AntiVirus
TR/Winwebsec.495616
7.11.143.202

avast!
Win32:Adware-gen [Adw]
2014.9-140416

AVG
Win32/Heur
2015.0.3503

Bitdefender
Adware.Generic.333296
1.0.20.530

Bkav FE
W32.HfsAutoA
1.3.0.4959

Clam AntiVirus
W32.Adware.InstallCore
0.98/18355

Dr.Web
Adware.InstallCore.40
9.0.1.0106

Emsisoft Anti-Malware
Adware.Generic.333296
8.14.04.16.11

ESET NOD32
Win32/InstallCore (variant)
8.9685

F-Prot
W32/InstallCore.C.gen
v6.4.7.1.166

F-Secure
Adware.Generic.333296
11.2014-16-04_4

G Data
Adware.Generic.333296
14.4.24

IKARUS anti.virus
AdWare.SuspectCRC
t3scan.1.6.1.0

MicroWorld eScan
Adware.Generic.333296
15.0.0.318

NANO AntiVirus
Trojan.Win32.InstallCore.bdstfq
0.28.0.59288

Rising Antivirus
PE:Adware.Agent!1.6A2E
23.00.65.14414

Sophos
Install Core Installer
4.98

Total Defense
Win32/InstallCore!Adware
37.0.10881

Trend Micro House Call
HV_INSTALLCORE_CA2268C4.TOMC
7.2.106

Vba32 AntiVirus
Adware.InstallCore.gen
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28286

File size:
1 MB (1,070,720 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\angry-birds-rio.exe

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:5EyrCWiwk8ZQ64sEOTE2/SiOUCWv3l/EElGDyjXlT3BDp94:5rEuyzylT3B99

Entry address:
0xC1CC9

Entry point:
55, 8B, EC, 83, C4, F0, B8, A1, E1, 48, 00, E8, E4, E6, FF, FF, 33, AF, 53, E9, 00, DD, 84, 7F, B3, DF, 17, B0, F9, D5, F2, 60, 8C, B9, CA, 9E, 8B, B9, E1, 90, 80, A0, 7B, 82, 9D, 80, 2D, 75, 0F, C4, 8E, 7B, 87, 56, 02, 9C, 58, 85, 97, 21, B5, DE, 3B, 86, 0A, 1A, BA, 6D, 61, CC, 4C, 42, 61, 92, A1, 82, 55, C7, BC, D1, 38, 21, FD, 3C, CB, 9F, 35, 68, 27, BC, 9D, 8E, 4F, D3, 18, 71, B2, 0D, 0B, BA, B4, 68, B0, 6C, 8B, A3, C6, 4F, 25, 0D, E9, 92, DD, 90, 05, F8, 31, 8D, 9F, 53, B1, 38, 05, 23, F9, 9D, 75, 9D...
 
[+]

Entropy:
6.7532

Developed / compiled with:
Microsoft Visual C++

Code size:
786.5 KB (805,376 bytes)

Remove angry-birds-rio.exe - Powered by Reason Core Security