facemoods.exe

InstallCore© Installer

Volonet Ltd

The application facemoods.exe, “InstallCore© Installer” by Volonet has been detected as adware by 9 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from i.facemoods.com.
Publisher:
InstallCore ©  (signed by Volonet Ltd)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1, 0, 0, 9

MD5:
85f37ed62fd22de5750ffeeb92ffd10b

SHA-1:
7194df2626cd6cc783d742509daa63e5f7a09ee6

SHA-256:
d0a08732938d49d02b0cdc10b1fce90e3973450762cd139cfa5d7d7addefa3f6

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 3:09:06 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.115.36

avast!
Win32:InstallCore-BA [PUP]
2014.9-140620

Bkav FE
W32.Clodf0b.Trojan
1.3.0.4562

Comodo Security
Heur.Suspicious
17316

Dr.Web
Adware.Funmoods.3
9.0.1.0171

ESET NOD32
Win32/SweetIM (variant)
8.9084

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

Reason Heuristics
PUP.Installer.Volonet.J
14.8.7.21

Rising Antivirus
Trojan.Win32.Generic.128686F5
23.00.65.14618

File size:
379.7 KB (388,824 bytes)

Product version:
1, 0, 0, 9

Copyright:
Copyright © InstallCore

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\facemoods.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/24/2010 12:00:00 AM

Valid to:
11/23/2012 11:59:59 PM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel-Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
27228002C4368B8985B0D57BC7FE75CC

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:3PuZGmtr8rrnIPU6IN9+FVOpBozE0fHbdTTj4mUlNTtU8zBrXngAbPdpYil:3PuZGmtUISCFVm6E0fHbdTT0mWNiaPzb

Entry address:
0xE1CD0

Entry point:
60, BE, 00, E0, 48, 00, 8D, BE, 00, 30, F7, FF, C7, 87, 10, 57, 0A, 00, 3A, 50, B8, 9D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.7643

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
336 KB (344,064 bytes)

The file facemoods.exe has been seen being distributed by the following URL.

Remove facemoods.exe - Powered by Reason Core Security