facemoods.exe

Volonet Ltd

The application facemoods.exe, “Powered by InstallCore” by Volonet has been detected as adware by 22 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
Facemoods  (signed by Volonet Ltd)

Product:
Facemoods

Description:
Powered by InstallCore

Version:
2.0.1.73

MD5:
beb6aea51fcce55735f4abd0dbd5bbc2

SHA-1:
0abc67d1ca50ba131e9008e77c4fcca4faaaee9f

SHA-256:
105d7a58a6fd274b698b97ddd6348fd4fc633cc5892bf844718a29ec6eed27c3

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/9/2024 2:50:24 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adtool.InstallCore.Gen.2
7.1.1

AhnLab V3 Security
Adware/Win32.FoxTab
2013.03.22

Avira AntiVirus
TR/Agent.623420
7.11.105.20

avast!
Win32:PUP-gen [PUP]
2014.9-160203

AVG
Adware InstallCore
2017.0.2844

Dr.Web
Adware.Funmoods.3, is riskware program Program.InstallCore.1
9.0.1.034

Emsisoft Anti-Malware
Application.InstallCore.AW
8.16.02.03.01

ESET NOD32
Win32/InstallCore (variant)
10.9459

Fortinet FortiGate
W32/InstallCore.A
2/3/2016

F-Prot
W32/InstallCore.I2.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.176.11239

Kaspersky
not-a-virus:HEUR:WebToolbar.Win32.InstallCore
14.0.0.717

Malwarebytes
Adware.InstallCore
v2016.02.03.01

McAfee
Artemis!7FB33E433521
5600.6500

NANO AntiVirus
Riskware.Win32.InstallCore.nxzhi
0.22.8.51404

Quick Heal
Trojan.InstallCore.a
2.16.12.00

Reason Heuristics
PUP.installCore.Installer (M)
16.2.3.13

Sophos
PUA 'Install Core Installer'
5.13

SUPERAntiSpyware
Trojan.Agent/Gen-Falleg[Cont]
9346

Trend Micro House Call
TROJ_GEN.F47V1104
7.2.34

Vba32 AntiVirus
BScope.Malware-Cryptor.Sinba.C
3.12.24.3

ViRobot
Trojan.Win32.A.InstallCore.625368.A
2011.4.7.4223

File size:
653.7 KB (669,400 bytes)

Product version:
2.0.1.73

Copyright:
Copyright © InstallCore

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\facemoods.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/23/2010 10:00:00 PM

Valid to:
11/23/2012 9:59:59 PM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel-Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
27228002C4368B8985B0D57BC7FE75CC

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4NiAu56FXmvwZXfmksDdleq/hu6JhyMsgD/ClUU7LMb:vsxmItfmfdleqZb7EflUsMb

Entry address:
0x15DED0

Entry point:
60, BE, 00, 20, 4D, 00, 8D, BE, 00, F0, F2, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
564 KB (577,536 bytes)

Remove facemoods.exe - Powered by Reason Core Security