powerisosetup-2508118.exe

The application powerisosetup-2508118.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
MD5:
30219436a77e24c06818b0ebae697794

SHA-1:
503018cb0ff232fb146a71b4f1f509fa9e57cb4e

SHA-256:
c7c20fc0fbc0e259109502d270447dcfb6c93d39ebeb4f9408272d2377d660c2

Scanner detections:
19 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/16/2024 5:12:39 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
7.11.144.48

AVG
Adware Skodna.Bundle.CA
2014.0.4189

Bkav FE
W32.Clodd4d.Trojan
1.3.0.4613

Comodo Security
ApplicUnwnt
18124

Dr.Web
Adware.Downware.8529
9.0.1.05190

ESET NOD32
Win32/InstallCore.BY potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/FirseriaInstaller
11/1/2014

F-Prot
W32/InstallCore.R3.gen
v6.4.7.1.166

K7 AntiVirus
Unwanted-Program
13.176.11806

Malwarebytes
v2014.11.01.02

McAfee
Artemis!5BF518743A65
5600.6960

NANO AntiVirus
Riskware.Win32.InstallCore.dfuuot
0.28.2.62671

Qihoo 360 Security
Win32/Virus.Adware.94c
1.0.0.1015

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.141030

Sophos
Install Core
4.94

Trend Micro House Call
TROJ_GEN.F47V1120
7.2.305

Vba32 AntiVirus
3.12.26.0

VIPRE Antivirus
InstallCore.b
24254

File size:
604.2 KB (618,688 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\powerisosetup-2508118.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:GkOyMJfsGMZUosic0DbyLl1PTQszmc+88Q5AK4fXUr67jE2fAs3N2hWpAeJZ:/OyMJfsjZUop1a1sMmcoQ9Gdo2VN2

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8580

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

Remove powerisosetup-2508118.exe - Powered by Reason Core Security