whitesmokeinstaller_9128.exe

InstallCore© Installer

WhiteSmoke Inc

The application whitesmokeinstaller_9128.exe, “InstallCore© Installer” by WhiteSmoke Inc has been detected as adware by 12 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
InstallCore ©  (signed by WhiteSmoke Inc)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1.0.0.8

MD5:
a36c9a4aa047dd99182ccbe7483d7f9f

SHA-1:
57eb4de6f848b1213456042689154c09ecba7bae

SHA-256:
9f31743124fbea35565657839c5cb407dfa07beb7787ebb22e5ab9cb85f0c911

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 10:07:22 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.97.32

avast!
Win32:InstallCore-BA [PUP]
2014.9-151031

Comodo Security
Heur.Suspicious
16782

Dr.Web
Adware.InstallCore.3
9.0.1.0304

ESET NOD32
Win32/InstallCore (variant)
9.8697

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

Malwarebytes
Adware.Agent
v2015.10.31.07

Reason Heuristics
PUP.WhiteSmoke.InstallCoreC.Installer (M)
15.10.31.7

Sophos
Install Core Installer
4.91

Trend Micro House Call
TROJ_GEN.RCBH1KQ
7.2.304

Vba32 AntiVirus
AdWare.WhiteSmoke
3.12.22.3

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
2011.4.7.4223

File size:
444.8 KB (455,504 bytes)

Product version:
1, 0, 0, 9

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2011 7:00:00 PM

Valid to:
7/7/2013 6:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64048D72F9FFEF12A43FC4F4CEA580E3

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:pzSmXRVP6q+xwmuTaTseZeIGj23xueOFDTUbD0mnMMei:pFB56q+xwmueTsrmueEYA8MMei

Entry address:
0xFA920

Entry point:
60, BE, 00, 50, 49, 00, 8D, BE, 00, C0, F6, FF, C7, 87, 10, 17, 0B, 00, 62, E2, CC, 72, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8553

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
408 KB (417,792 bytes)

Remove whitesmokeinstaller_9128.exe - Powered by Reason Core Security