Installer.dll

Installer

The module Installer.dll has been detected as a potentially unwanted program by 5 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup. While running, it connects to the Internet address www.ibbalance.com on port 443.
Product:
Installer

Version:
1.0.0.0

MD5:
4fa2124f06593c6fe62cd522d319aa29

SHA-1:
7c6494b182aff60d48d440c95d4d2158c6829928

SHA-256:
481c6de70c8bb3786c80ddeb9741d4b70f9bfb2950a727fc40c39242d620e06a

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 1:29:53 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Potentially harmful program Downloader.BFM
2014.0.4007

Baidu Antivirus
Adware.MSIL.Proxomoto
4.0.3.14822

ESET NOD32
MSIL/Adware.Proxomoto.A application
7.0.302.0

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.26.3

Zillya! Antivirus
Adware.Agent.Win32.10359
2.0.0.1899

File size:
15.5 KB (15,872 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Installer.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\windows\microsoft\sogr\installer.dll

File PE Metadata
Compilation timestamp:
7/9/2014 1:56:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:qjnHqoH+KcKkT9NpX82D9xhjO2UD0afWwOVFCrt3YViwiLRiqiai6iji3jmMU:qjnHyb/DnhCphORv

Entry address:
0x54AE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
13.5 KB (13,824 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove Installer.dll - Powered by Reason Core Security