PreInstallValidator.exe

PreInstallValidator

Adknowledge

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application PreInstallValidator.exe has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer, however the file is not signed with an authenticode signature from a trusted source. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from install.browsersafeguard.com.
Publisher:
Adknowledge

Product:
PreInstallValidator

Version:
1.0.0.0

MD5:
2f9599c2345d251c3109b2d992b999ee

SHA-1:
7c59c853cee1ce9a406b126df49f3b4754a2603c

SHA-256:
b82f9b1716da0c8239d374f484c710ccc2aff1a4a64ce23bb598f3ec5ac14611

Scanner detections:
4 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/18/2024 8:25:37 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge.T
14.3.1.4

Sophos
Mal/MSIL-BA
4.95

Trend Micro House Call
TROJ_GEN.R0C1H08LB13
7.2.347

XVirus List
Win.Detected
2.3.31

File size:
40.5 KB (41,472 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Adknowledge 2013

Original file name:
PreInstallValidator.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\preinstallvalidator.exe

File PE Metadata
Compilation timestamp:
12/11/2013 4:19:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:EmFPVikGme3awxwTci+9L94H5I9f5lrPNCkvy/bNqWPoAthBB2iSlN:xFPwkGme3awxwTDMx4ZI9f5lrPNabAAU

Entry address:
0xB73E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.6563

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
38 KB (38,912 bytes)

The file PreInstallValidator.exe has been seen being distributed by the following URL.

Remove PreInstallValidator.exe - Powered by Reason Core Security