applianflv.exe

SafeInstaller

SecureInstall, LLC

This is the InstallX/InstallIQ download manager and installer that will bundle offers during setup for additional PUPs and other unwanted software. The application applianflv.exe by SecureInstall has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the InstallIQ Installation Manager installer. The file has been seen being downloaded from dl2.v47installer.com and multiple other hosts.
Publisher:
SafeInstall, LLC  (signed by SecureInstall, LLC)

Product:
SafeInstaller

Description:
Safe Installer

Version:
1.0.30.0

MD5:
e8de92789b2da009a54a44e9d337a7a4

SHA-1:
0e8b08dd93d9e38a3c485c21da741881ab2e4cd9

SHA-256:
34a742f289efa9e6ee7de66a0e26d561fbdab39a271c69837661440a3250323b

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the InstallIQ (by InstallX) software bundler that may include toolbars and other browser extensions offers.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/24/2024 10:55:56 PM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Hoax.W32.ArchSMS
2.1.4+

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
Win32:PUP-gen [PUP]
2014.9-140808

AVG
MultiBundle
2015.0.3528

Dr.Web
Adware.Searcher.2593
9.0.1.080

ESET NOD32
Win32/InstallIQ (variant)
8.9462

herdProtect (fuzzy)
2014.5.21.2

K7 AntiVirus
Unwanted-Program
13.176.11302

Kaspersky
not-a-virus:Downloader.NSIS.Agent
14.0.0.3440

Malwarebytes
PUP.Optional.SafeInstall.A
v2014.03.21.08

McAfee
Artemis!E8DE92789B2D
5600.7184

NANO AntiVirus
Trojan.Win32.Searcher.csnymk
0.28.0.57630

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.SecureInstall.K
14.8.8.0

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
23.00.65.14319

Sophos
DomainIQ pay-per install
4.97

Total Defense
Win32/Tnega.DVfFGD
37.0.10955

Trend Micro House Call
TROJ_GEN.F47V0225
7.2.98

VIPRE Antivirus
InstallIQ Installer
26794

XVirus List
Win32.Detected
2.4.7

File size:
1.6 MB (1,714,280 bytes)

Product version:
1.0.30.0

Copyright:
Copyright (C) 2014

Original file name:
safeinstall.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallIQ Installation Manager

Language:
English (United States)

Common path:
C:\users\{user}\downloads\applianflv.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/18/2013 6:00:00 PM

Valid to:
11/24/2014 6:00:00 AM

Subject:
CN="SecureInstall, LLC", O="SecureInstall, LLC", L=Sartell, S=Minnesota, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
073E5B30FA98352DDA4DA1FD7215A72F

File PE Metadata
Compilation timestamp:
2/19/2014 12:11:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:8Ymq3HplWsv2PhscqWzBvqeVR9Vo1bb8MnaG9kIueboeBT7sAzUrTmksThYe1yEf:WZLr1qhFnNk9uoe9zUvsTpyEw8BBh

Entry address:
0x4DE9D

Entry point:
E8, F0, 3A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B0, 69, 52, 00, E8, 2D, 2B, 00, 00, E8, BD, 3C, 00, 00, 0F, B7, F0, 6A, 02, E8, 83, 3A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 64, 34, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.9761

Code size:
974.5 KB (997,888 bytes)

The file applianflv.exe has been seen being distributed by the following 4 URLs.

Remove applianflv.exe - Powered by Reason Core Security