DownloadManagerSetup.exe

Click run software

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application DownloadManagerSetup.exe by Click run software has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.downloadmanagerapp.com.
Publisher:
Click run software  (signed and verified)

MD5:
bbf91ff9abea3d68384094dab31d9401

SHA-1:
1148f361b230ed4b336bca6925a3eb573ad1f30c

SHA-256:
db546f05df317778f139e90fd99d4751c8a0ae4f421dc57a466ef37be0dc9cde

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/20/2024 2:48:29 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
W32.Sality
2.1.4+

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.142.34

AVG
MalSign.InstallCore
2015.0.3389

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.1487

Bkav FE
HW32.Laneul
1.3.0.4959

Comodo Security
Application.Win32.ClickRun.A
18074

Dr.Web
Adware.InstallCore.99, Adware.InstallCore.122
9.0.1.0219

ESET NOD32
Win32/InstallCore.BY potentially unwanted application
8.7.0.302.0

Fortinet FortiGate
W32/InstallCore.BF
8/7/2014

F-Prot
W32/InstallCore.R.gen
v6.4.6.5.141

K7 AntiVirus
Unwanted-Program
13.176.11702

McAfee
RDN/Generic.bfr!fj
5600.7045

NANO AntiVirus
Riskware.Win32.InstallCore.cyqicy
0.28.0.60577

Panda Antivirus
PUP/MultiToolbar.A
14.08.07.08

Reason Heuristics
PUP.Installer.Clickrunsoftware.U
14.8.7.20

Rising Antivirus
PE:Malware.InstallCore!6.4
23.00.65.14805

Trend Micro House Call
TROJ_GEN.F47V0330
7.2.219

Vba32 AntiVirus
3.12.26.0

VIPRE Antivirus
Click run software
28156

File size:
660.8 KB (676,624 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\downloadmanagersetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/19/2012 3:00:00 AM

Valid to:
4/20/2013 2:59:59 AM

Subject:
CN=Click run software, O=Click run software, STREET=63 Rotshylid Shderot, L=Tel-Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A243E49C0DAF69F7C5ACF083EB184161

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:hhEcJfsUNlpDF/GOwewIXDkhzVtQyy6bboOegjcfV0ddwnV8BUpKf:0cJfsExGO1wIX2HQGqgjcC7c2BUpKf

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file DownloadManagerSetup.exe has been seen being distributed by the following URL.

Remove DownloadManagerSetup.exe - Powered by Reason Core Security