firefox_update.exe

TODO:

File Verified

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application firefox_update.exe by File Verified has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
TODO: <Company name>  (signed by File Verified)

Product:
TODO: <Product name>

Description:
Firefox_Update

Version:
1.0.0.1

MD5:
519816c8c572a4bbe29380e0100c56b4

SHA-1:
1cf71bfde9bba7a32666888469d3df7bfef879bd

SHA-256:
a8c8f77c9a3f7d1ca5b489a4594df34af4a176afc69c470f5cf34dae95daee36

Scanner detections:
20 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 4:36:51 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallMetrix
7.1.1

AhnLab V3 Security
PUP/Win32.InstallMonster
2015.03.29

avast!
Win32:Adware-gen [Adw]
2014.9-150703

AVG
Adware Generic5.CHSX.dropper
2016.0.3156

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Installmonster-8
0.98/21411

Comodo Security
ApplicUnwnt.Win32.InstallMetrix.A
21573

Dr.Web
Trojan.Domaiq.7
9.0.1.087

ESET NOD32
Win32/Adware.InstallMetrix.E application
7.0.302.0

F-Prot
W32/A-215008ab
v6.4.7.1.166

herdProtect (fuzzy)
2015.7.3.8

IKARUS anti.virus
PUA.InstallMetrix
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.185.13943

NANO AntiVirus
Riskware.Win32.InstallMonster.dhazif
0.28.6.62995

Norman
InstallMetrix.E
11.20150328

Panda Antivirus
Trj/Genetic.gen
15.03.28.08

Reason Heuristics
PUP.InstallMetrix
15.3.28.20

Sophos
Install Metrix
4.98

VIPRE Antivirus
Threat.4150696
34232

Zillya! Antivirus
Adware.InstallMonster.Win32.42
2.0.0.1977

File size:
1013.1 KB (1,037,440 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United States)

Common path:
C:\users\{user}\downloads\firefox_update.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/9/2014 6:00:00 PM

Valid to:
10/10/2015 5:59:59 PM

Subject:
CN=File Verified, OU=File Verified, O=File Verified, STREET="660 4th Street, Suite 427", L=San Francisco, S=California, PostalCode=94107, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3218B54F8331C296189D5EA9E74030ED

File PE Metadata
Compilation timestamp:
11/3/2014 1:12:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:TP3YNwjfcu0+MOKtUZkTn2NX7D+T5ZPfY8d2:bYNcfJ0zUZk+H+13k

Entry address:
0x679A

Entry point:
E8, 50, 1B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, 0D, 41, 00, 89, 0D, 04, 0D, 41, 00, 89, 15, 00, 0D, 41, 00, 89, 1D, FC, 0C, 41, 00, 89, 35, F8, 0C, 41, 00, 89, 3D, F4, 0C, 41, 00, 66, 8C, 15, 20, 0D, 41, 00, 66, 8C, 0D, 14, 0D, 41, 00, 66, 8C, 1D, F0, 0C, 41, 00, 66, 8C, 05, EC, 0C, 41, 00, 66, 8C, 25, E8, 0C, 41, 00, 66, 8C, 2D, E4, 0C, 41, 00, 9C, 8F, 05, 18, 0D, 41, 00, 8B, 45, 00, A3, 0C, 0D, 41, 00, 8B, 45, 04, A3, 10, 0D, 41, 00, 8D, 45, 08, A3, 1C, 0D, 41...
 
[+]

Entropy:
7.8254  (probably packed)

Code size:
39.5 KB (40,448 bytes)

Remove firefox_update.exe - Powered by Reason Core Security