infigo_setup_ic.exe

Internet software

MAVIN LOG, S.L.

The application infigo_setup_ic.exe, “Internet software Setup ” by MAVIN LOG, S.L has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.infigo-cleaner.com.
Publisher:
Web Application   (signed by MAVIN LOG, S.L.)

Product:
Internet software

Description:
Internet software Setup

Version:
5.7.3.6

MD5:
09e3e67e145ee0fdf7555f4916259e48

SHA-1:
9bba8c74ed07bd05b8f46568073e914911539a5d

SHA-256:
326ff98a7a4ccfcff2b2e084cff847dd56a40be62d30eee53561f6430c670bb3

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 7:41:30 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Virut.Gen
7.11.30.172

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.16126

Comodo Security
Application.Win32.InstallCore.DSY
21358

ESET NOD32
Win32/InstallCore.WX potentially unwanted application
10.7.0.302.0

G Data
Win32.Application.InstallCore.EG
16.1.25

Malwarebytes
v2016.01.26.11

Reason Heuristics
PUP.installCore (M)
16.1.26.11

Vba32 AntiVirus
Malware-Cryptor.InstallCore.gen
3.12.26.4

File size:
832 KB (852,000 bytes)

Product version:
1.3.0

Copyright:
Installer

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\infigo_setup_ic.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/2/2014 5:00:00 PM

Valid to:
11/1/2016 4:59:59 PM

Subject:
CN="MAVIN LOG, S.L.", O="MAVIN LOG, S.L.", L=Las Palmas de Gran Canaria, S=Las Palmas, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2A7C2F47EC1B4B9270591EE153868BBB

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:wdcVUZkKBXLwv9afcNsMjnoHKRZYPNWwUg+1W65UHQ+L:wyrKBXc9wcNcKRZLJWUUx

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8485

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file infigo_setup_ic.exe has been seen being distributed by the following URL.

Remove infigo_setup_ic.exe - Powered by Reason Core Security