PreInstallValidator.exe

PreInstallValidator

Adknowledge

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application PreInstallValidator.exe has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer, however the file is not signed with an authenticode signature from a trusted source. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from d890t4wyanc8w.cloudfront.net and multiple other hosts.
Publisher:
Adknowledge

Product:
PreInstallValidator

Version:
1.0.0.0

MD5:
9e14496264269cf1c15697af0f52e7f3

SHA-1:
772113b2609ff7645b22aafe8f4c58decb5d6a32

SHA-256:
08422256b63dd0535a975d41aec2e7398a9a07d3e57e4dc15fb1982b8a22df76

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 8:49:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge.T
14.2.22.1

File size:
18.5 KB (18,944 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Adknowledge 2013

Original file name:
PreInstallValidator.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\preinstallvalidator.exe

File PE Metadata
Compilation timestamp:
1/15/2014 8:31:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:hbZNY4ChJfcafPD/P+dbqGe2LfaZv4+E4cEu4ZQLcs:hs4TRqHPCXl

Entry address:
0x5EDE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.1448

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

The file PreInstallValidator.exe has been seen being distributed by the following 2 URLs.

Remove PreInstallValidator.exe - Powered by Reason Core Security