icreinstall_free_download_managersetup_v1.0.1.1573_release.exe

Click run software

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_free_download_managersetup_v1.0.1.1573_release.exe by Click run software has been detected as adware by 20 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from ptf.com and multiple other hosts. While running, it connects to the Internet address os.solvefile.com on port 80 using the HTTP protocol.
Publisher:
Click run software  (signed and verified)

MD5:
fc1ba32518688db75cf86f1f9ce3b252

SHA-1:
6d5e56f70c7c30f5492569659e8879b3535be293

SHA-256:
fa0227515f0ce75d7dd642d00b245bf841fdce96864ca69616e551cdb022a731

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 4:48:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.268794
996

Avira AntiVirus
APPL/Downloader.Gen6
7.11.135.154

AVG
MalSign.InstallCore
2015.0.3474

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.14514

Bitdefender
Adware.Generic.268794
1.0.20.670

Comodo Security
Application.Win32.ClickRun.A
17899

Dr.Web
Adware.InstallCore.53
9.0.1.0134

Emsisoft Anti-Malware
Adware.Generic.268794
8.14.05.14.08

ESET NOD32
Win32/InstallCore.AJ (variant)
8.9515

Fortinet FortiGate
Adware/Fam.NB
5/14/2014

F-Secure
Adware.Generic.268794
11.2014-14-05_4

G Data
Adware.Generic.268794
14.5.24

K7 AntiVirus
Unwanted-Program
13.176.11378

MicroWorld eScan
Adware.Generic.268794
15.0.0.402

Panda Antivirus
PUP/MultiToolbar.A
14.05.14.09

Reason Heuristics
PUP.Installer.Clickrunsoftware.x
14.8.7.20

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14512

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.gen
3.12.24.3

VIPRE Antivirus
Click run software
27172

File size:
1 MB (1,054,696 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_free_download_managersetup_v1.0.1.1573_release.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/18/2012 6:00:00 PM

Valid to:
4/19/2013 5:59:59 PM

Subject:
CN=Click run software, O=Click run software, STREET=63 Rotshylid Shderot, L=Tel-Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A243E49C0DAF69F7C5ACF083EB184161

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:8IGAsVUxnYLjG+sy/U68gwMt6iasA7C7uK9RuDzeqQIW6bmGLOSAEPC:KVUtUjG+b8gwMgivR90lT6COfEPC

Entry address:
0xC6150

Entry point:
55, 8B, EC, 83, C4, F0, B8, 94, 56, 40, 00, E8, DD, E9, FF, FF, 08, 2B, C6, 3B, 70, 08, 74, 0A, C7, 05, C0, 15, 47, 00, 06, 00, 00, 00, E8, 8A, FE, FF, FF, 03, DE, 8B, C3, 5E, 5B, C3, 8D, 40, 00, 53, 56, 57, 8B, D8, 33, FF, 8B, 03, A9, 00, 00, 00, 80, 74, 0B, 25, FC, FF, FF, 7F, 03, F8, 03, D8, 8B, 03, A8, 02, 75, 13, 8B, F3, 8B, C6, E8, 58, FE, FF, FF, 8B, 46, 08, 03, F8, 03, D8, 83, 23, FE, 8B, C7, 5F, 5E, 5B, C3, 53, 56, 57, 55, 83, C4, F4, 8B, FA, 8B, F0, C6, 04, 24, 00, 8B, C6, E8, 96, FE, FF, FF, 8B...
 
[+]

Entropy:
6.9428

Developed / compiled with:
Microsoft Visual C++

Code size:
805 KB (824,320 bytes)

The file icreinstall_free_download_managersetup_v1.0.1.1573_release.exe has been seen being distributed by the following 2 URLs.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)