wecpsetup.exe

Open Source Developer

The application wecpsetup.exe by Open Source Developer has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Open Source Developer  (signed and verified)

MD5:
77ad991359fe92d1aae32e5e5390ba8f

SHA-1:
75263d1659e892bb7df5a347366462f352162874

SHA-256:
f14042c498ac9eaa1712d1b7b69f3df2d3d6a078a2e701b77f255644153a028b

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 6:55:03 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.InstallCore.80
9.0.1.05190

ESET NOD32
Win32/InstallCore.AZ potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.S.gen
4.6.5.141

File size:
1.1 MB (1,193,424 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\wecpsetup.exe

Digital Signature
Authority:
Unizeto Technologies S.A.

Valid from:
7/11/2012 3:34:47 AM

Valid to:
7/11/2013 3:34:47 AM

Subject:
E=admin@devlopex.com, CN=Open Source Developer, OU=Open Source Developer, O=Open Source Developer, C=CY

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
3B0D24754C74CB103F49DCDB864049BD

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:LmIfxJvGdc9j86tsOUy4Acn/vrzSqOq9lTR/l0Y+ixbLOBmf:LmuvyW86tsXyt0LzdO8llWiB64f

Entry address:
0xD6630

Entry point:
55, 8B, EC, 83, C4, F0, B8, 10, E1, 40, 00, E8, E2, F7, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
869.5 KB (890,368 bytes)

Remove wecpsetup.exe - Powered by Reason Core Security