whitesmokeinstaller_9128.exe

InstallCore© Installer

WhiteSmoke Inc

The application whitesmokeinstaller_9128.exe, “InstallCore© Installer” by WhiteSmoke Inc has been detected as adware by 12 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from get.whitesmoke.com.
Publisher:
InstallCore ©  (signed by WhiteSmoke Inc)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1.0.0.8

MD5:
00b052eb8b739e859198e49463395209

SHA-1:
51d036e88ba3a1beb83ae47b93f3922be3032853

SHA-256:
113682d5e13c5a9dd93bf2f10479a8caf1e6fc5033ae85927d9c3fa77fb558e7

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 1:07:42 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.176.180

avast!
Win32:InstallCore-BA [PUP]
2014.9-141009

Comodo Security
Heur.Suspicious
19711

ESET NOD32
Win32/InstallCore (variant)
8.10515

Fortinet FortiGate
Riskware/InstallCore
10/9/2014

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

K7 AntiVirus
Trojan
13.183.13584

Malwarebytes
Adware.Agent
v2014.10.09.03

Reason Heuristics
PUP.Installer.WhiteSmoke.Y
14.10.9.3

Sophos
Install Core Installer
4.98

VIPRE Antivirus
WhiteSmoke (not malicious)
33688

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
2011.4.7.4223

File size:
446.8 KB (457,480 bytes)

Product version:
1, 0, 0, 9

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\whitesmokeinstaller_9128.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/9/2008 8:00:00 PM

Valid to:
7/8/2011 7:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4261300AF5254B751250B0CDBDA6CE61

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:LzSlllrH+akcP4WzykFx9z2/c14UesMKs2dEvFAG29dWgMMAbs:LQ/reKgWzykFx9z2jUPMKsTtR29dWgM0

Entry address:
0xFE370

Entry point:
60, BE, 00, 80, 49, 00, 8D, BE, 00, 90, F6, FF, C7, 87, 10, 17, 0B, 00, 36, 83, BE, 9C, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8523

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
412 KB (421,888 bytes)

The file whitesmokeinstaller_9128.exe has been seen being distributed by the following URL.

Remove whitesmokeinstaller_9128.exe - Powered by Reason Core Security