ICReinstall_spss_tr.exe

W32Setup

The application ICReinstall_spss_tr.exe by W32Setup has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
W32Setup  (signed and verified)

MD5:
9b4fe83feae2039f6ea966374024c6dc

SHA-1:
6863a1d7b66823f4a33d3946794556b0a9ba155f

SHA-256:
b043daacddd8f33f56a616121c122c4ba28471ba98abb6c2218214be7b11b615

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/7/2024 2:04:48 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.W32Setup
2015.0.3472

Dr.Web
Trojan.MulDrop5.10078
9.0.1.0136

ESET NOD32
Win32/InstallCore.OK (variant)
8.9771

Fortinet FortiGate
Riskware/InstallCore
5/16/2014

Malwarebytes
v2014.05.16.08

McAfee
Artemis!9B4FE83FEAE2
5600.7128

Reason Heuristics
PUP.W32Setup.T
14.7.27.14

Trend Micro House Call
TROJ_GEN.F47V0507
7.2.136

Vba32 AntiVirus
3.12.26.0

VIPRE Antivirus
InstallCore.b
28986

File size:
683.3 KB (699,728 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_spss_tr.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/28/2014 3:00:00 AM

Valid to:
4/29/2015 2:59:59 AM

Subject:
CN=W32Setup, O=W32Setup, STREET=28 Lenelblome St., L=Tel-Aviv, S=Israel, PostalCode=651307, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D6D42503AA8B6EA0ECBAEF215FA32DCA

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:voFa4MfpJRS3VCYxF6vZx2qsGwejMH72P5zWjtMuyvitXbNT5vRyTu:voFFM3RSlzF6vZps7ej82sjtM7ak

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove ICReinstall_spss_tr.exe - Powered by Reason Core Security