whitesmokeinstaller_9128.exe

InstallCore© Installer

WhiteSmoke Inc

The application whitesmokeinstaller_9128.exe, “InstallCore© Installer” by WhiteSmoke Inc has been detected as adware by 16 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from get.whitesmoke.com.
Publisher:
InstallCore ©  (signed by WhiteSmoke Inc)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1.0.0.8

MD5:
e5116788d4f88ca49b18ccf829f3151b

SHA-1:
ab2e9e3618075baa652849e2a86e2bbf937eda50

SHA-256:
e4a59d5d9f8bb2b1e028abe64105aa606b20d5f1085af79e790940a1e1e51136

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 6:48:14 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.98.160

avast!
Win32:InstallCore-BA [PUP]
2014.9-150306

Comodo Security
Heur.Suspicious
16840

Dr.Web
Adware.InstallCore.3
9.0.1.065

ESET NOD32
Win32/InstallCore (variant)
9.8738

Fortinet FortiGate
Adware/WhiteSmoke
3/6/2015

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

IKARUS anti.virus
not-a-virus:AdWare.Win32.WhiteSmoke
t3scan.2.0.127

Kaspersky
not-a-virus:AdWare.Win32.WhiteSmoke
14.0.0.2387

Malwarebytes
Adware.Agent
v2015.03.06.01

Reason Heuristics
PUP.Installer.WhiteSmoke
15.3.6.13

Sophos
Install Core Installer
4.91

Trend Micro House Call
TROJ_GEN.F47V1112
7.2.65

Vba32 AntiVirus
AdWare.WhiteSmoke
3.12.22.3

VIPRE Antivirus
WhiteSmoke (not malicious)
20960

ViRobot
Trojan.Win32.A.Agent.530256[UPX]
2011.4.7.4223

File size:
444.8 KB (455,504 bytes)

Product version:
1, 0, 0, 9

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\whitesmokeinstaller_9128.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2011 8:00:00 PM

Valid to:
7/7/2013 7:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64048D72F9FFEF12A43FC4F4CEA580E3

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:xzSmXRVP6q+xwmuTaTseZeIGj23Zi2U2u2WuZpMMeE2:xFB56q+xwmueTsrONbWuvMMe/

Entry address:
0xFA920

Entry point:
60, BE, 00, 50, 49, 00, 8D, BE, 00, C0, F6, FF, C7, 87, 10, 17, 0B, 00, 62, E2, CC, 72, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8553

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
408 KB (417,792 bytes)

The file whitesmokeinstaller_9128.exe has been seen being distributed by the following URL.

Remove whitesmokeinstaller_9128.exe - Powered by Reason Core Security