pdf_2012setup_v1.0.1.1.exe

Click run software

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application pdf_2012setup_v1.0.1.1.exe by Click run software has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore monetization download manager to download additional third party applications that may be unwanted by the user. The file has been seen being downloaded from dnld.installcore.com.
Publisher:
Click run software  (signed and verified)

MD5:
66c9378da73f75a4249a018ac49d8c5b

SHA-1:
73ee2229cb26593a0efab1701d9fe67b56996f79

SHA-256:
7268dee1eeb2e6e41e8930967a2fbffe70e3dfeeaf1d2d372c8c80ac500a5e94

Scanner detections:
9 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/7/2024 7:26:08 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen6
7.11.128.158

Bkav FE
W32.HfsAutoA
1.3.0.4923

Comodo Security
Application.Win32.ClickRun.A
17718

Panda Antivirus
Adware/MultiToolbar
14.04.27.05

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Clickrunsoftware.T
14.8.7.20

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14425

VIPRE Antivirus
Click run software
26060

File size:
1020.3 KB (1,044,752 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Digital Signature
Authority:
COMODO CA Limited

Valid from:
4/19/2012 1:00:00 AM

Valid to:
4/20/2013 12:59:59 AM

Subject:
CN=Click run software, O=Click run software, STREET=63 Rotshylid Shderot, L=Tel-Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A243E49C0DAF69F7C5ACF083EB184161

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:86ITT4J6YdDENs9kXxVnpwbSv0TY8Sfn9zLoQTQNPBNFNFqTb99tmGl7lHqIstI1:8F5UD1kBVnCbiujSf3TQr+VTmy51LjB

Entry address:
0xC94B0

Entry point:
55, 8B, EC, 83, C4, F0, B8, E8, 7A, 41, 00, E8, 83, F0, FF, FF, 25, 64, 11, 47, 00, 8B, C0, FF, 25, 60, 11, 47, 00, 8B, C0, FF, 25, 5C, 11, 47, 00, 8B, C0, FF, 25, 58, 11, 47, 00, 8B, C0, FF, 25, C4, 11, 47, 00, 8B, C0, FF, 25, 54, 11, 47, 00, 8B, C0, FF, 25, 50, 11, 47, 00, 8B, C0, FF, 25, 4C, 11, 47, 00, 8B, C0, FF, 25, DC, 11, 47, 00, 8B, C0, FF, 25, D8, 11, 47, 00, 8B, C0, FF, 25, D4, 11, 47, 00, 8B, C0, FF, 25, 48, 11, 47, 00, 8B, C0, FF, 25, 44, 11, 47, 00, 8B, C0, FF, 25, EC, 11, 47, 00, 8B, C0, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
818 KB (837,632 bytes)

The file pdf_2012setup_v1.0.1.1.exe has been seen being distributed by the following URL.

Remove pdf_2012setup_v1.0.1.1.exe - Powered by Reason Core Security