icreinstall_winrar 5.10.exe

Downloads Manager Ltd

The installer utilizes InstallCore which may bundle about 3-4 offers for various ad-supported toolbars, extensions and utilities. The application icreinstall_winrar 5.10.exe by Downloads Manager has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download WinRAR archiver but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Downloads Manager Ltd  (signed and verified)

MD5:
715498c50cfaf06d293f62a43c51df86

SHA-1:
bc0042f96b026b07cb196b4a810dfb632c5187b2

SHA-256:
e220a9b6ca37ea1666cf3f6a778ec936a8a0a42a6361ed8d56e0fcca1fcb8f07

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 1:43:37 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3254

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.141221

ESET NOD32
Win32/InstallCore.QC (variant)
8.10412

F-Prot
W32/InstallCore.AC.gen
v6.4.7.1.166

McAfee
Artemis!715498C50CFA
5600.6910

Norman
InstallCore.WQEB
11.20141221

Reason Heuristics
PUP.DownloadsManager.W
14.12.21.10

Trend Micro House Call
Suspicious_GEN.F47V0911
7.2.355

VIPRE Antivirus
InstallCore
33082

File size:
742.8 KB (760,584 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\icreinstall_winrar 5.10.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/15/2014 8:00:00 PM

Valid to:
5/16/2015 7:59:59 PM

Subject:
CN=Downloads Manager Ltd, O=Downloads Manager Ltd, STREET=Level 27 PWC Tower 188 Quay St, L=Auckland City, S=Auckland, PostalCode=1010, C=NZ

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
5E4DA60FFC5160823A52FCFF2AC150A9

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:UW6vpxPrKsl/6nehj7O1po99OEvw5TSMWwCWIym8hctWX55ftyFaBoGHFE4AxgVL:UvvHOsEehn2po99OEvI7WwCZd8hctWXt

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8890

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to os.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdnus.solvefile.com  (207.189.109.121:80)

TCP (HTTP):
Connects to cdneu.webfilescdn.com  (65.254.40.36:80)

Remove icreinstall_winrar 5.10.exe - Powered by Reason Core Security