firefox_update.exe

TODO:

File Verified

This is the InstallMetrix bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application firefox_update.exe by File Verified has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the InstallMetrix Software installer. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
TODO: <Company name>  (signed by File Verified)

Product:
TODO: <Product name>

Description:
Firefox_Update

Version:
1.0.0.1

MD5:
32fcffc97411d231b005e024a5bdc059

SHA-1:
c88043a0f1d11f01d16bb10ed12018eb3b5325e4

SHA-256:
8bc40755a5123d169f9244a6a9f15e3fa2aa15499b6a4e08ef2cb6d63bcb19e3

Scanner detections:
21 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 4:33:15 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallMetrix
7.1.1

AhnLab V3 Security
PUP/Win32.InstallMonster
2015.03.29

Avira AntiVirus
ADWARE/InstallMet.hc
3.6.1.96

avast!
Win32:Adware-gen [Adw]
2014.9-150703

AVG
Adware Generic5.CHSX.dropper
2016.0.3156

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Installmonster-8
0.98/21411

Comodo Security
ApplicUnwnt.Win32.InstallMetrix.A
21573

Dr.Web
Trojan.Domaiq.7
9.0.1.087

ESET NOD32
Win32/Adware.InstallMetrix.E application
7.0.302.0

F-Prot
W32/A-215008ab
v6.4.7.1.166

herdProtect (fuzzy)
2015.7.3.8

IKARUS anti.virus
PUA.InstallMetrix
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.185.13943

NANO AntiVirus
Riskware.Win32.InstallMonster.dhazif
0.28.6.62995

Norman
InstallMetrix.E
11.20150328

Panda Antivirus
Trj/Genetic.gen
15.03.28.08

Reason Heuristics
PUP.InstallMetrix
15.3.28.20

Sophos
Install Metrix
4.98

VIPRE Antivirus
Threat.4150696
34232

Zillya! Antivirus
Adware.InstallMonster.Win32.42
2.0.0.1977

File size:
1013.1 KB (1,037,440 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2014

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallMetrix Software

Language:
English (United States)

Common path:
C:\users\{user}\downloads\firefox_update.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/9/2014 6:00:00 PM

Valid to:
10/10/2015 5:59:59 PM

Subject:
CN=File Verified, OU=File Verified, O=File Verified, STREET="660 4th Street, Suite 427", L=San Francisco, S=California, PostalCode=94107, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
3218B54F8331C296189D5EA9E74030ED

File PE Metadata
Compilation timestamp:
11/3/2014 1:12:50 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:TP3YNwjfcu0+MOKtUZkTn2NX7D+T5ZPfY8dV:bYNcfJ0zUZk+H+13z

Entry address:
0x679A

Entry point:
E8, 50, 1B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 08, 0D, 41, 00, 89, 0D, 04, 0D, 41, 00, 89, 15, 00, 0D, 41, 00, 89, 1D, FC, 0C, 41, 00, 89, 35, F8, 0C, 41, 00, 89, 3D, F4, 0C, 41, 00, 66, 8C, 15, 20, 0D, 41, 00, 66, 8C, 0D, 14, 0D, 41, 00, 66, 8C, 1D, F0, 0C, 41, 00, 66, 8C, 05, EC, 0C, 41, 00, 66, 8C, 25, E8, 0C, 41, 00, 66, 8C, 2D, E4, 0C, 41, 00, 9C, 8F, 05, 18, 0D, 41, 00, 8B, 45, 00, A3, 0C, 0D, 41, 00, 8B, 45, 04, A3, 10, 0D, 41, 00, 8D, 45, 08, A3, 1C, 0D, 41...
 
[+]

Entropy:
7.8254  (probably packed)

Code size:
39.5 KB (40,448 bytes)

Remove firefox_update.exe - Powered by Reason Core Security