whitesmokeinstaller_9128.exe

WhiteSmoke Installer

WhiteSmoke Inc

The application whitesmokeinstaller_9128.exe by WhiteSmoke Inc has been detected as adware by 12 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
WhiteSmoke  (signed by WhiteSmoke Inc)

Product:
WhiteSmoke Installer

Version:
1.1.2.92

MD5:
5eaf71beace6308ec2bf69377f9b9714

SHA-1:
72a6598fd47884cc4960ee494634eac109c74ae8

SHA-256:
1ec52999b06155dec68b9775ab0d7887df40e320940e233dc11d4de7370f06d5

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 10:31:21 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.135.48

avast!
Win32:InstallCore-AZ [PUP]
2014.9-150811

Dr.Web
Adware.InstallCore.3
9.0.1.0223

ESET NOD32
Win32/InstallCore (variant)
9.9509

Fortinet FortiGate
Riskware/InstallCore
8/11/2015

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

Malwarebytes
Adware.Agent
v2015.08.11.10

Reason Heuristics
PUP.WhiteSmoke.Installer (M)
15.8.11.22

Rising Antivirus
PE:PUF.InstallCore!1.9DE1
23.00.65.15809

Sophos
Install Core Installer
4.98

Trend Micro House Call
TROJ_GRAYBIRD_0000014.TOMA
7.2.223

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
2011.4.7.4223

File size:
479.3 KB (490,832 bytes)

Product version:
1.1.2.92

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\whitesmokeinstaller_9128.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2011 5:00:00 PM

Valid to:
7/7/2013 4:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64048D72F9FFEF12A43FC4F4CEA580E3

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:RzS8l31+pyWCCgpB1FI5mmVuXhKZv2qPAINFr+d3tPfJ3A5QJgMMJD:RJ51N5rg5XVLUqYeFCddnJwIgMMJD

Entry address:
0x10A310

Entry point:
60, BE, 00, C0, 49, 00, 8D, BE, 00, 50, F6, FF, C7, 87, 10, 17, 0B, 00, 65, 17, 51, F0, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8522

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
444 KB (454,656 bytes)

Remove whitesmokeinstaller_9128.exe - Powered by Reason Core Security