icreinstall_softwareupdatesetup.exe

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_softwareupdatesetup.exe has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
MD5:
21661c1a4f3ce8e1d167c697ef1b128e

SHA-1:
93dc29b07cf2d69923778578294326408d36dd08

SHA-256:
f65b4b4d4cb6ff1326638b6496302bc82d834002a9feca430d69937b33f33d86

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 5:29:46 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.179.110

AVG
Skodna.Bundle
2015.0.3312

Bkav FE
W32.Clodd4d.Trojan
1.3.0.4959

Comodo Security
ApplicUnwnt
18124

Dr.Web
Adware.Downware.8529
9.0.1.0296

ESET NOD32
Win32/InstallCore.BY (variant)
8.10581

Fortinet FortiGate
Riskware/FirseriaInstaller
10/23/2014

F-Prot
W32/A-dbe1ec51
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.184.13718

Malwarebytes
v2014.10.23.08

McAfee
Artemis!5BF518743A65
5600.6968

NANO AntiVirus
Riskware.Win32.InstallCore.dfuuot
0.28.2.62671

Qihoo 360 Security
Win32/Virus.Adware.94c
1.0.0.1015

Reason Heuristics
PUP.InstallCore.Installer.FF
14.10.23.20

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141021

Sophos
Install Core
4.94

Trend Micro House Call
TROJ_GEN.F47V1120
7.2.296

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
InstallCore.b
34022

File size:
604.2 KB (618,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_softwareupdatesetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:GkOyMJfsGMZUosic0DbyLl1PTQszmc+88Q5AK4fXUr67jE2fAs3N2hWpAeJZ:/OyMJfsjZUop1a1sMmcoQ9Gdo2VN2

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file icreinstall_softwareupdatesetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_softwareupdatesetup.exe - Powered by Reason Core Security