pdfreadersetup.exe

InstallCore Ltd.

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application pdfreadersetup.exe by InstallCore has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.coolpdfreader.com.
Publisher:
InstallCore Ltd.  (signed and verified)

MD5:
af8ad46829fe89cabb6f035f15cf3e10

SHA-1:
4909e37b824a4b2e4e06e0f291f8072c19f5c9d6

SHA-256:
a7cc767677d5945df44874841c677156ff31151173f1faa35ec53237c1682251

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 12:59:53 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Adware InstallCore.ABR
2015.0.4522

Dr.Web
Adware.InstallCore.47
9.0.1.05190

ESET NOD32
Win32/InstallCore.BH potentially unwanted application
7.0.302.0

Kaspersky
HEUR:Hoax.Win32.ArchSMS
15.0.0.562

Norman
Gen:Variant.Graftor.188825
08.02.2016 04:24:12

Reason Heuristics
PUP.installCore.Installer (M)
16.2.12.20

Sophos
PUA 'Install Core'
5.23

File size:
654.3 KB (669,968 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\downloads\pdfreadersetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/21/2012 12:00:00 AM

Valid to:
2/20/2013 11:59:59 PM

Subject:
CN=InstallCore Ltd., OU=Support, O=InstallCore Ltd., STREET=Nisim Aloni 21, L=Tel Aviv, S=N/A, PostalCode=62919, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0088971791FBF6CE4920268CDF6A0A825F

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:yb95f8C1Rr9SuFqqsJrKsXtp9sx4n70E3FOZD1OstHHIQMZgnJe7O5o1Scz:yb/EudsKsXDD71q7K1gnJe2ox

Entry address:
0x106920

Entry point:
60, BE, 00, B0, 46, 00, 8D, BE, 00, 60, F9, FF, C7, 87, 10, B7, 0C, 00, 93, E0, 7B, 8A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
7.7656

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
624 KB (638,976 bytes)

The file pdfreadersetup.exe has been seen being distributed by the following URL.

Remove pdfreadersetup.exe - Powered by Reason Core Security