logologoquiz_ic.exe

App Zeus Ltd

The application logologoquiz_ic.exe by App Zeus has been detected as a potentially unwanted program by 14 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
App Zeus Ltd  (signed and verified)

MD5:
072ae97b1e08cf21dc3205a4f5e71f35

SHA-1:
e50ecef0ad1ed65079a6bfcee74fec4d5db36b6f

SHA-256:
3ff3caa5be3df7187b5583bfdc178c8ce65d3a2c85dec277e7facccf782b0c23

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 9:16:55 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.InstallCore
2016.01.18

Avira AntiVirus
PUA/InstallCore.Gen
8.3.2.4

AVG
InstallCore
2017.0.2806

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.16313

Dr.Web
Adware.InstallCore.72
9.0.1.073

ESET NOD32
Win32/InstallCore.AW potentially unwanted (variant)
10.12884

Fortinet FortiGate
Riskware/InstallCore
3/13/2016

F-Prot
W32/InstallCore.P.gen
v6.4.7.1.166

McAfee
Artemis!072AE97B1E08
5600.6462

Reason Heuristics
PUP.InstallCore.ENG (M)
16.3.13.10

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16311

Sophos
Generic PUA OF (PUA)
4.98

SUPERAntiSpyware
PUP.Wajam/Variant
9268

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.26.4

File size:
1 MB (1,087,696 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\logologoquiz_ic.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/17/2012 2:00:00 AM

Valid to:
10/18/2013 1:59:59 AM

Subject:
CN=App Zeus Ltd, O=App Zeus Ltd, STREET=19 c Kehilat Padova street, L=Tel Aviv, S=Israel, PostalCode=69404, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
008FD31DFE8DE288675E494B5C22DE28CC

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:gNj+WFWjm1CmTFnFc5mZC0MTC9mwfNWekNGLXvboZL:gNj+WFWjmUMFnOsw4mwfgek0zvby

Entry address:
0xCAD90

Entry point:
55, 8B, EC, 83, C4, F0, B8, C0, 2D, 41, 00, E8, E4, DF, FF, FF, 24, 2C, 01, 74, 05, 0F, B7, 5C, 24, 30, 8B, C3, 83, C4, 44, 5B, C3, 8B, C0, FF, 25, 5C, 41, 47, 00, 8B, C0, FF, 25, 58, 41, 47, 00, 8B, C0, FF, 25, 54, 41, 47, 00, 8B, C0, FF, 25, 50, 41, 47, 00, 8B, C0, FF, 25, 4C, 41, 47, 00, 8B, C0, FF, 25, 48, 41, 47, 00, 8B, C0, FF, 25, 44, 41, 47, 00, 8B, C0, FF, 25, 40, 41, 47, 00, 8B, C0, 53, 56, BE, E0, 35, 47, 00, 83, 3E, 00, 75, 3A, 68, 44, 06, 00, 00, 6A, 00, E8, A8, FF, FF, FF, 8B, C8, 85, C9, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
828 KB (847,872 bytes)

Remove logologoquiz_ic.exe - Powered by Reason Core Security