downloadmanagersetup.exe

The application downloadmanagersetup.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
MD5:
8d437350a56d31577436e9ea9391e2fa

SHA-1:
d869ebdcb522bbb5850bde7713ce442852f3fdca

SHA-256:
dd1dd7c551643a35f6b79b839579f14ee1427d2827ce9aff1fcebf5ab07c1ae3

Scanner detections:
26 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/10/2024 7:29:19 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.InstallCore.AM
5828757

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.188.80

avast!
Win32:InstallCore-BI [PUP]
141119-1

AVG
InstallCore
2015.0.3282

Bitdefender
Application.InstallCore.AM
1.0.20.1635

Bkav FE
W32.HfsAutoA
1.3.0.4959

Clam AntiVirus
Win.Adware.Installcore-81
0.98/21511

Comodo Security
Application.Win32.ClickRun.D
20172

Dr.Web
Adware.InstallCore.56
9.0.1.05190

Emsisoft Anti-Malware
Application.InstallCore.AM
9.0.0.4570

ESET NOD32
Win32/InstallCore.K potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.V2.gen
4.6.5.141

F-Secure
Application.InstallCore.AM
11.2014-23-11_1

G Data
Application.InstallCore.AM
14.11.24

K7 AntiVirus
Unwanted-Program
13.185.14098

Malwarebytes
PUP.Adware.InstallCore
v2014.11.23.10

MicroWorld eScan
Application.InstallCore.AM
15.0.0.981

NANO AntiVirus
Trojan.Win32.InstallCore.uwnxq
0.28.6.63474

nProtect
Abuse-Worry/W32.InstallCore.1031144
14.11.21.01

Panda Antivirus
PUP/MultiToolbar.A
14.11.23.10

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.InstallCore!6.73F
23.00.65.141121

SUPERAntiSpyware
Adware.InstallCore
10220

VIPRE Antivirus
Threat.4754767
35010

File size:
1007 KB (1,031,144 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\downloadmanagersetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:+f/RMpsocGdc9tzeFK9iQVg6aHjIlW83d0ERwbP2a4FU9c:IJM7/mnVDa8toua4+

Entry address:
0xC2380

Entry point:
55, 8B, EC, 83, C4, F0, B8, CC, 36, 40, 00, E8, CE, E7, FF, FF, 00, E8, FD, F0, FF, FF, C3, E9, D7, 19, 00, 00, EB, E5, 8B, 45, FC, 5F, 5E, 5B, 59, 59, 5D, C3, 8D, 40, 00, 55, 8B, EC, 51, 53, 56, 57, 8B, D8, 33, C0, A3, C0, 95, 46, 00, 80, 3D, BC, 95, 46, 00, 00, 75, 1F, E8, 66, F7, FF, FF, 84, C0, 75, 16, C7, 05, C0, 95, 46, 00, 08, 00, 00, 00, C7, 45, FC, 08, 00, 00, 00, E9, 61, 01, 00, 00, 33, C9, 55, 68, 7A, 24, 40, 00, 64, FF, 31, 64, 89, 21, 80, 3D, 49, 90, 46, 00, 00, 74, 0A, 68, C4, 95, 46, 00, E8...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
788 KB (806,912 bytes)

Remove downloadmanagersetup.exe - Powered by Reason Core Security