syncitunes-setup.exe

Web Install

This installer uses the CNET Download.com download manager (private label) in order to provide monetized offerings to end users. These offers could include ad-supported toolbars or various web browser extensions. The application syncitunes-setup.exe by Web Install has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the DownloadCom Spot Install installer. The installer is marketed through download protals and search ads as Apple's iTunes but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Web Install  (signed and verified)

MD5:
95df906a1f81e37d18184ad3f97dfc66

SHA-1:
b47d477b56d4f9e177ee52650719a3d038292208

SHA-256:
c5e14c075fbd41aaedb425affb00845e66f7edf3af4426705b1843ba151ec1a2

Scanner detections:
8 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/24/2024 2:29:33 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downware
7.1.1

avast!
Adware-BGE [PUP]
150203-1

Dr.Web
Adware.Downware.1159
9.0.1.05190

ESET NOD32
Detection.Undefined
7.0.302.0

K7 AntiVirus
Trojan
13.198.15071

NANO AntiVirus
Riskware.Nsis.Downware.dlgjls
0.30.0.296

Reason Heuristics
PUP.Installer.CBS
15.2.24.17

VIPRE Antivirus
Threat.4782786
37788

File size:
640.8 KB (656,200 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
DownloadCom Spot Install (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\syncitunes-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/19/2013 5:00:00 PM

Valid to:
3/19/2016 4:59:59 PM

Subject:
CN=Web Install, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Web Install, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6F93708E2A9DB00DA7666A9EA9A5FA00

File PE Metadata
Compilation timestamp:
6/22/2012 11:07:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:xXNRmR4TUPiaOP/SYG25CHFpJfMwp71q4OVNx6fRWH5GuJ:xX44UDOS20vtMwZ1BENx8WZ7

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9445

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file syncitunes-setup.exe has been seen being distributed by the following URL.

Remove syncitunes-setup.exe - Powered by Reason Core Security