whitesmokeinstaller_8899.exe

InstallCore© Installer

WhiteSmoke Inc

The application whitesmokeinstaller_8899.exe, “InstallCore© Installer” by WhiteSmoke Inc has been detected as adware by 13 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from get.whitesmoke.com.
Publisher:
InstallCore ©  (signed by WhiteSmoke Inc)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1.0.0.8

MD5:
113f362dda10f0ec3ef7e20b619d1c11

SHA-1:
9e100acd864a74bae6d5e7a1b4cbe16b4575d304

SHA-256:
5d8b9199553659b4e39fd12046c56f582557f58a19c1d25cd902b1cf1f2e00dc

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 6:05:29 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.106.104

avast!
Win32:InstallCore-BA [PUP]
2014.9-140510

Comodo Security
Heur.Suspicious
17074

Dr.Web
Adware.InstallCore.3
9.0.1.0130

ESET NOD32
Win32/InstallCore (variant)
8.8891

Fortinet FortiGate
W32/Tra.B!tr
5/10/2014

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

Malwarebytes
Adware.Agent
v2014.05.10.12

McAfee
Generic.tra!b
5600.7135

Reason Heuristics
PUP.Installer.WhiteSmoke.Y
14.8.7.22

Sophos
Install Core Installer
4.93

VIPRE Antivirus
WhiteSmoke (not malicious)
22204

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
2011.4.7.4223

File size:
446.8 KB (457,480 bytes)

Product version:
1, 0, 0, 9

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\whitesmokeinstaller_8899.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/9/2008 7:00:00 PM

Valid to:
7/8/2011 6:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4261300AF5254B751250B0CDBDA6CE61

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:LzSlllrH+akcP4WzykFx9z2/c14UesMsqtoZykRwTwMMAbn:LQ/reKgWzykFx9z2jUPMLovRwTwMMAbn

Entry address:
0xFE380

Entry point:
60, BE, 00, 80, 49, 00, 8D, BE, 00, 90, F6, FF, C7, 87, 10, 17, 0B, 00, 36, 83, BE, 9C, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8521

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
412 KB (421,888 bytes)

The file whitesmokeinstaller_8899.exe has been seen being distributed by the following URL.

Remove whitesmokeinstaller_8899.exe - Powered by Reason Core Security