itunes_dsetup.exe

The application itunes_dsetup.exe has been detected as a potentially unwanted program by 20 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
MD5:
7dd9e9f303b96f2c7bb7adb966679663

SHA-1:
c6063e931e8fdceb0514b18b27d8195fda718826

SHA-256:
a3745d187e6f7fd6dac667248d5a230db27a513c0575418ffe62a2a83c20b957

Scanner detections:
20 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/9/2024 1:34:42 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.644083
538

Agnitum Outpost
Adware.Generic
7.1.1

Bitdefender
Adware.Generic.644083
1.0.20.1140

Bkav FE
W32.Clodce0.Trojan
1.3.0.4562

Dr.Web
Adware.InstallCore.133
9.0.1.0228

Emsisoft Anti-Malware
Adware.Generic.644083
8.15.08.16.05

ESET NOD32
Win32/InstallCore.FJ (variant)
9.9129

F-Secure
Adware.Generic.644083
11.2015-16-08_1

G Data
Adware.Generic.644083
15.8.22

IKARUS anti.virus
Backdoor.Hupigon
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.175.10735

Malwarebytes
v2015.08.16.05

McAfee
Artemis!7DD9E9F303B9
5600.6672

MicroWorld eScan
Adware.Generic.644083
16.0.0.684

Reason Heuristics
PUP.InstallCore.Bundler (M)
15.8.16.5

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15814

Trend Micro House Call
TROJ_GEN.F47V1114
7.2.228

VIPRE Antivirus
Trojan.Win32.Generic
25076

File size:
615.5 KB (630,280 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\itunes_dsetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:8+yMJfsG2CQppBVjEui7dSoQyZfXL1HrnPdJIfFfCmK8R9Fb6D6g5a:hyMJfs5BZVjEVG4fXLt6N9a6g5

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.7779

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file itunes_dsetup.exe has been seen being distributed by the following 2 URLs.

http://files.downloadsmart.net/i/1119/5385/.../itunes_dsetup.exe

Remove itunes_dsetup.exe - Powered by Reason Core Security