install.exe

IEInstaller

Pull Trends

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application install.exe by Pull Trends has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer.
Publisher:
Pull Trends  (signed and verified)

Product:
IEInstaller

Version:
1.0.0.0

MD5:
da6f8ef518d0e68159c99766f6d2d68c

SHA-1:
d75c00d79b529b4c5dc2634090de7579ec88acaa

SHA-256:
9a5e2d47c3a055c37ffb78c2418c52bddb37ca31d3e339ac419673e20f4dc829

Scanner detections:
13 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 8:48:54 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Click
7.1.1

Avira AntiVirus
ADWARE/IERedirector.87040
8.3.1.6

AVG
iBryte
2016.0.2913

Bitdefender
Gen:Variant.Zusy.146257
1.0.20.1655

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.iBryte.538
9.0.1.0331

G Data
Gen:Variant.Zusy.146257
15.11.25

IKARUS anti.virus
AdWare.IERedirector
t3scan.1.9.5.0

Kaspersky
Trojan.Win32.Startpage
14.0.0.1059

MicroWorld eScan
Gen:Variant.Zusy.146257
16.0.0.993

Reason Heuristics
PUP.Adknowledge.PullTrends.Installer (M)
15.11.27.2

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
41226

File size:
95.3 KB (97,632 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2015

Original file name:
IEInstaller.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\apps\2.0\qpdybve5.7hv\0409ncww.yeg\mywe..erxp_65118c3ef8e168a4_0001.0000_abc9cf1fc129ec86\install.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/6/2015 7:00:00 PM

Valid to:
1/7/2016 6:59:59 PM

Subject:
CN=Pull Trends, O=Pull Trends, STREET="4600 Madison Ave, 10th FL", L=Kansas City, S=MO, PostalCode=64112, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2DB408BA9ECD129D99939D263A3C8574

File PE Metadata
Compilation timestamp:
6/18/2015 3:51:40 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:D/fWjh/+90uvEfG5Wjh/+90uvEfGbWjh/+90uvEfGXHzV+s/GOVrim:DnWjh290uvEfG5Wjh290uvEfGbWjh29Z

Entry address:
0x170DE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.4234

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
84.5 KB (86,528 bytes)

Remove install.exe - Powered by Reason Core Security