firefox_setup_21.0.exe

Secure Installer

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application firefox_setup_21.0.exe by Secure Installer has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as the free Mozilla Firefox web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Secure Installer  (signed and verified)

MD5:
ae9319dd180b82949e69d166a3292870

SHA-1:
9c45aa390d2390a29c3c4a1401055ae435e7e5bf

SHA-256:
9f8dc49c482c7486967c6f77a46165dbbff3e59b8d578018289229b5ee1da3b1

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 5:44:40 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
160209-2

AVG
Adware Generic5.BDFX
2015.0.4522

Dr.Web
Trojan.Crossrider1.49350
9.0.1.05190

ESET NOD32
Win32/InstallCore.BL potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.installCore.SecureInstaller.Installer (M)
16.2.11.9

VIPRE Antivirus
Threat.4786018
47028

File size:
603.1 KB (617,608 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\firefox_setup_21.0.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
9/25/2012 12:00:00 AM

Valid to:
9/25/2013 11:59:59 PM

Subject:
CN=Secure Installer, O=Secure Installer, STREET=720 Market Street, STREET=5th floor, L=San Francisco, S=CA, PostalCode=94102, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C3507C1ADDE6B4C52E5426990F85CA2B

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:WCyMJfsFJHCmVDYUGr3gHRV0k+Ts+MleJ3RddPbrwDUUfezUImxQK7:WCyMJfsHi0YLr3gA8le/PnwDr2zc

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.7560

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

Remove firefox_setup_21.0.exe - Powered by Reason Core Security