transformers.exe

The application transformers.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from installerlaunch-mm1.com.
MD5:
e25322583b59aa4563dd4f57c5bbb4c1

SHA-1:
eb824001e8d9633fb2198a168083e899099f1553

SHA-256:
a601edcbc472195bff40ed6f68ea53c88f988d80e11c01ab090cf7a500906e9c

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 3:18:05 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.367530
5813571

avast!
Win32:InstallCore-CZ [PUP]
151226-0

AVG
Adware MultiBundle.AB
2015.0.4477

Clam AntiVirus
Adware.Installcore-137
0.98/21198

Dr.Web
Adware.InstallCore.567
9.0.1.05190

Emsisoft Anti-Malware
Adware.Generic.367530
10.0.0.5366

ESET NOD32
Win32/InstallCore.H potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.B.gen
4.6.5.141

Norman
Adware.Generic.367530
17.12.2015 06:34:11

Sophos
PUA 'Install Core Installer'
5.22

VIPRE Antivirus
Threat.4150696
46020

File size:
539.1 KB (552,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\transformers.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Rd3AwEFtvWlBsjQ84uBetDNJK3tmwWGsJDx0:vjEuuQTK3tXWGAq

Entry address:
0x10D740

Entry point:
60, BE, 00, 20, 49, 00, 8D, BE, 00, F0, F6, FF, C7, 87, 10, B7, 0C, 00, 58, C4, A0, 0A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8071

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
496 KB (507,904 bytes)

The file transformers.exe has been seen being distributed by the following URL.

Remove transformers.exe - Powered by Reason Core Security