icreinstall_vlc_media_player_ar.exe

Symbolicom Holdings Ltd

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_vlc_media_player_ar.exe by Symbolicom Holdings has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The installer is marketed through download protals and search ads as the VideoLAN VLC media player but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Symbolicom Holdings Ltd  (signed and verified)

MD5:
f1a9b86bcf0707d2ed33e8fa3e1b7d00

SHA-1:
0285a5cd2bccdba0bf40855d004e988a47e238d3

SHA-256:
c0af951b56db91a62b576d4b515b56504f75fd0b7c6162bf0d70a8177846324f

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 6:29:03 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.133.204

Dr.Web
Trojan.MulDrop5.10078
9.0.1.0141

ESET NOD32
Win32/InstallCore.JE.gen (variant)
8.9477

herdProtect (fuzzy)
2014.5.21.8

Malwarebytes
v2014.05.21.08

Reason Heuristics
PUP.SymbolicomHoldings.FF
14.3.22.16

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14519

Vba32 AntiVirus
3.12.24.3

VIPRE Antivirus
InstallCore.b
26884

File size:
697.9 KB (714,624 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_vlc_media_player_ar.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/8/2014 1:00:00 AM

Valid to:
1/9/2015 12:59:59 AM

Subject:
CN=Symbolicom Holdings Ltd, OU=Symbolicom, O=Symbolicom Holdings Ltd, STREET=Trident Cyprus, STREET=115 Griva Digeni Avenue Trident Centre, STREET=Limassol, L=Limassol, S=Cyprus, PostalCode=3101, C=CY

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C4B90F930A0BA04B111E671526916207

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:evpghu68Okv8a8I2E7DFouu9TSfPoGYdF0nqk203TkyEe2bOFbWRMUJDMy1TXzHC:evmhuBYjgDjaYGfQH203d/+f2UDTXz

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

Remove icreinstall_vlc_media_player_ar.exe - Powered by Reason Core Security