downloadtoolbarformicrosoftinternetexplorer-setup.exe

Web Install

This installer uses the CNET Download.com download manager (private label) in order to provide monetized offerings to end users. These offers could include ad-supported toolbars or various web browser extensions. The application downloadtoolbarformicrosoftinternetexplorer-setup.exe by Web Install has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the DownloadCom Spot Install installer. The installer is marketed through download protals and search ads as Internet Explorer but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Web Install  (signed and verified)

MD5:
f54197eff3b516dcb4a301a39eef400b

SHA-1:
cbfac311eb82a11f186d5db6f56c3559df4f6024

SHA-256:
bc4a671260ba1947686fd7c0165c3ae36000911fa8b2de7fce9ebdb5450037ba

Scanner detections:
10 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/2/2024 7:04:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downware
7.1.1

avast!
Win32:Adware-BGE [PUP]
2014.9-150408

Clam AntiVirus
Win.Adware.Agent-6650
0.98/19265

Dr.Web
Adware.Downware.1159
9.0.1.098

ESET NOD32
Win32/DownloadAdmin
9.9765

K7 AntiVirus
Trojan
13.202.15530

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.59608

Reason Heuristics
PUP.Bundler.CBS
15.4.8.16

VIPRE Antivirus
WebInstall
28926

File size:
641.5 KB (656,864 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
DownloadCom Spot Install (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\downloadtoolbarformicrosoftinternetexplorer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/19/2013 8:00:00 PM

Valid to:
3/19/2016 7:59:59 PM

Subject:
CN=Web Install, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Web Install, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6F93708E2A9DB00DA7666A9EA9A5FA00

File PE Metadata
Compilation timestamp:
6/22/2012 2:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:XXNRmR4TUPiaOP/SYG25CHFpJfMwp71q4OVNx6fRWH5GuF:XX44UDOS20vtMwZ1BENx8WZj

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9446

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)