aviconvertersetup.exe

AVI Converter

Install Core

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application aviconvertersetup.exe, “AVI Converter Installer” by Install Core has been detected as adware by 27 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from apps.foxtab.com.
Publisher:
AVI Converter Tec  (signed by Install Core)

Product:
AVI Converter

Description:
AVI Converter Installer

Version:
3.1.0.0

MD5:
dcb297ae63e3859e496867a3dbbd988d

SHA-1:
3341333db58033dabd93ec16d6470f448da6aac1

SHA-256:
14d165d0c5f73f06f1b90550d00be2c838de7b4e4289538a5f736d9d8d117f17

Scanner detections:
27 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 6:10:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.InstallCore.AV
355

Agnitum Outpost
Adtool.InstallCore.Gen.2
7.1.1

AhnLab V3 Security
Adware/Win32.FoxTab
2013.08.17

Avira AntiVirus
7.11.96.250

avast!
Win32:InstallCore-F [PUP]
2014.9-160215

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.16215

Bitdefender
Application.InstallCore.AV
1.0.20.230

Bkav FE
W32.Clod80b.Trojan
1.3.0.4924

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0
16777

Dr.Web
Adware.InstallCore.13
9.0.1.046

Emsisoft Anti-Malware
Application.InstallCore.AV
8.16.02.15.08

ESET NOD32
Win32/InstallCore (variant)
10.8697

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

F-Secure
Application.InstallCore.AV
11.2016-15-02_2

G Data
Application.InstallCore.AV
16.2.22

K7 AntiVirus
Riskware
13.170.9306

Malwarebytes
Adware.InstallCore
v2016.02.15.08

McAfee
RDN/Generic PUP.x!b2g
5600.6489

MicroWorld eScan
Application.InstallCore.AV
17.0.0.138

NANO AntiVirus
Trojan.Win32.InstallCore.vnwkg
0.26.0.53954

Qihoo 360 Security
Win32/Application.09e
1.0.0.1015

Reason Heuristics
PUP.installCore.AVIConverterTec.Installer (M)
16.2.15.8

Rising Antivirus
PE:Trojan.Win32.Generic.1526E028!354869288
23.00.65.16213

Sophos
Install Core Installer
4.91

Trend Micro House Call
TROJ_GEN.RC1H1DB
7.2.46

Vba32 AntiVirus
WebToolbar.InstallCore
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20574

File size:
480.5 KB (492,040 bytes)

Product version:
3.1.0.0

Copyright:
Copyright © InstallCore

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\downloads\aviconvertersetup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/1/2011 7:00:00 PM

Valid to:
2/2/2012 6:59:59 PM

Subject:
CN=Install Core, O=Install Core, STREET=Nisim Aloni 21, L=Tel Aviv, S=Tel Aviv, PostalCode=62919, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2BCA6BFDAB7E5637BA8E7E9C6400CC75

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:o1pkfKb2DpcIDF7r9l0T77RGQsoxFmJKCF+tQ2+o8Wv4MM5uDL:omKyDpcqfn0T7Qo+km+MtWv4MMIDL

Entry address:
0x10D970

Entry point:
60, BE, 00, 50, 4A, 00, 8D, BE, 00, C0, F5, FF, C7, 87, 10, D7, 0B, 00, E3, 34, 41, 18, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
420 KB (430,080 bytes)

The file aviconvertersetup.exe has been seen being distributed by the following URL.

Remove aviconvertersetup.exe - Powered by Reason Core Security