The application facebook-video-calling.exe has been detected as a potentially unwanted program by 16 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the ironSource InstallCore engine to bundle additional software including toolbars and browser extensions. The file has been seen being downloaded from www.updatestar.com.
16 / 68
Uses the ironSource InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.
4/19/2014 8:05:38 PM UTC (4 days ago)
K7 Gateway Antivirus
Install Core Installer
4/19/2014 rev. 7
Trend Micro House Call
607.9 KB (622,520 bytes)
Executable application (Win32 EXE)
6/20/1992 12:22:17 AM
Packer / compiler:
Inno Setup v5.x - Installer Maker
36 KB (36,864 bytes)
The file facebook-video-calling.exe has been seen being distributed by the following URL.
The following files closely match facebook-video-calling.exe based on a fuzzy CTPH.
13 / 68 (PUP)
[100% match] (7add1cc1bd332859946298369ba82b909b93d34d)
Detection Incidence by Country