mediadownloadersetup.exe

Web Software generic

Download Beta (Alpha Criteria Ltd)

The application mediadownloadersetup.exe, “Web Software generic Setup ” by Download Beta (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.chucklehostbest.com.
Publisher:
Soft Web Installer   (signed by Download Beta (Alpha Criteria Ltd))

Product:
Web Software generic

Description:
Web Software generic Setup

Version:
4.5.5.1

MD5:
a2fc25d41dcecd9595b5fbef61a9c515

SHA-1:
e938c6ca1f3fe79dac68a1096b1b3311ba89eb97

SHA-256:
6f186f2336fe06681f7d2499ad670defa30cd399cb351e3b6b03138e59c7cee6

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/17/2025 2:53:51 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC.Installer (M)
16.5.24.4

File size:
910 KB (931,864 bytes)

Product version:
1.8.2

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\mediadownloadersetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/16/2015 6:50:13 AM

Valid to:
7/27/2016 8:53:04 AM

Subject:
CN=Download Beta (Alpha Criteria Ltd), O=Download Beta (Alpha Criteria Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B4B4166A3B4A9E9EFB16280151B2BE36

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:tqQ/trz+cUQMga+OXEiazmmSCQJZob2GumF:tqqt/UQMga+OTXCEZob2GJ

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9332

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file mediadownloadersetup.exe has been seen being distributed by the following URL.

Remove mediadownloadersetup.exe - Powered by Reason Core Security