avast-free-antivirus.exe

The application avast-free-antivirus.exe has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from download.dobreprogramy.pl and multiple other hosts a known adware distribution point operated by dobreprogramy sp. z o.o..
MD5:
a384341ab7a4cf91b5872efd1751d9b2

SHA-1:
384d06c257b5843fde23518d394c5d9a4f8f12ca

SHA-256:
899b805f260f02af6ae357c4aad919eddb7d265ba7c4dae4f494deb28175964f

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/23/2024 8:51:53 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.117.90

Comodo Security
Application.Win32.InstallCore.AM
17376

Dr.Web
Trojan.Packed.24524
9.0.1.045

ESET NOD32
Win32/InstallCore.CH (variant)
10.9122

Malwarebytes
v2016.02.14.12

Rising Antivirus
PE:PUA.XPACK-LNR!1.5594
23.00.65.16212

VIPRE Antivirus
InstallCore.b
23960

File size:
669.2 KB (685,248 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\avast-free-antivirus.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ayMJfsGnYrKnA0KSJCvBMuBKCdqQvI4T/6KaMbeWZ0auAikIp3Hl1PJIEcKb68ng:ayMJfsjr+8S4djCKDKoKkIp3+r61

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file avast-free-antivirus.exe has been seen being distributed by the following 2 URLs.

http://download.dobreprogramy.pl/.../x64

Remove avast-free-antivirus.exe - Powered by Reason Core Security