lipocodessuggestor.exe

Lipocodes Suggestor silent installer

Think Tank Labs, LLC

The application lipocodessuggestor.exe, “Lipocodes Suggestor silent installer for Internet Explorer, Mozilla Firefox and Google Chrome” by Think Tank Labs has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program FreeDuplicateRemover by LipoCodes Software. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
LipoCodes Software  (signed by Think Tank Labs, LLC)

Product:
Lipocodes Suggestor silent installer

Description:
Lipocodes Suggestor silent installer for Internet Explorer, Mozilla Firefox and Google Chrome

Version:
1.1.5.0

MD5:
52f2ed26366fe669ff7868e4e0cb130c

SHA-1:
b1443beb38e21b405f63a2c6dcd55cb8846aff0a

SHA-256:
d5e9280c3cbcfc74452b3b85bf52d735268f8016098a72ceaee048175f4e1693

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
4/19/2024 1:30:33 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Searcher.2627
9.0.1.0291

NANO AntiVirus
Trojan.Win32.Generic.dbxlbd
0.30.0.296

nProtect
Trojan-Clicker/W32.OutBrowse.576576
15.03.06.01

Reason Heuristics
PUP.ThinkTankLabs.LipoCodesSoftware.Installer (M)
15.10.18.13

File size:
563.1 KB (576,576 bytes)

Product version:
2012.02.07.1641

Copyright:
© LipoCodes Software

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\Program Files\tvsoft\lipocodessuggestor.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
4/14/2011 2:17:41 AM

Valid to:
4/12/2012 2:11:13 AM

Subject:
CN="Think Tank Labs, LLC", O="Think Tank Labs, LLC", L=Newport, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B68DF215AD36D

File PE Metadata
Compilation timestamp:
12/6/2009 2:20:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:/HT0adDR7OPws7ilhnqlFzTlvBIfcbMb3r:/HYM97ps7NDbe7

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9566

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file lipocodessuggestor.exe has been discovered within the following program.

FreeDuplicateRemover  by LipoCodes Software
www.lipocodes.com/FreeDuplicateRemover
About 6% of users remove it
 
Powered by Should I Remove It?

Remove lipocodessuggestor.exe - Powered by Reason Core Security