installmanager.exe

The application installmanager.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from secure.fordcdnsecure.com.
MD5:
34b1aa956a27c0ae6d534c5f91770ac6

SHA-1:
7f866b6139140aa6b53bb0ed9894702faecea9a9

SHA-256:
cf9059c0ca67d28a0eee0312877b6ad4cb1c008bb236911c6e466bbf0fde14bd

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
5/16/2024 2:02:09 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.194.74

Baidu Antivirus
PUA.Win32.VMDetector
4.0.3.141211

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/InstallMonetizer.BD potentially unwanted application
7.0.302.0

Malwarebytes
Riskware.Vmdetector
v2014.12.11.07

NANO AntiVirus
Trojan.Nsis.Downloader.djhpgw
0.28.6.63850

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.141209

SUPERAntiSpyware
Adware.InstallMonetizer
10184

File size:
323.4 KB (331,183 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\installmanager.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:NFJ06wabOKCNndLD7pJ59ECadigTZXwVCTtZ4rt5q2pd5A8WwFK:h5bOxnV7pBAdZXwVC/4rbJd5A8I

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installmanager.exe has been seen being distributed by the following URL.

Remove installmanager.exe - Powered by Reason Core Security