whitesmokeinstaller_9147.exe

WhiteSmoke Installer

WhiteSmoke Inc

The application whitesmokeinstaller_9147.exe by WhiteSmoke Inc has been detected as adware by 12 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
WhiteSmoke  (signed by WhiteSmoke Inc)

Product:
WhiteSmoke Installer

Version:
1.1.2.92

MD5:
a2ba27161db8a4cc66e45b73cebe1e73

SHA-1:
324cce25fa44f5552b68983f75bbbc35cbc7c6e4

SHA-256:
c304c816d72f4865938f67c572d575643a5c4cbbc3540edc78ac378e5697d76d

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/19/2024 11:32:14 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Agent.490832
7.11.22.138

avast!
Win32:Malware-gen
2014.9-151113

Clam AntiVirus
Trojan.InstallCore
0.98/18155

Comodo Security
Heur.Suspicious
11449

Dr.Web
Adware.InstallCore.3
9.0.1.0317

Emsisoft Anti-Malware
Win32.Malware!IK
8.15.11.13.08

ESET NOD32
Win32/InstallCore (variant)
9.6866

G Data
Win32:Malware-gen
15.11.22

IKARUS anti.virus
Win32.Malware
t3scan.1.1.113.0

McAfee
Artemis!A2BA27161DB8
5600.6583

Norman
W32/WhiteSmoke.AM
11.20151113

Reason Heuristics
PUP.WhiteSmoke.Installer (M)
15.11.13.8

File size:
479.3 KB (490,832 bytes)

Product version:
1.1.2.92

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\whitesmokeinstaller_9147.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/28/2011 8:00:00 PM

Valid to:
7/7/2013 7:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64048D72F9FFEF12A43FC4F4CEA580E3

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ozS8l31+pyWCCgpB1FI5mmVuXhKZv2qPAINFr+1yy0g4WFwuCsaMMJB:oJ51N5rg5XVLUqYeFC1yDWFDMMMJB

Entry address:
0x10A310

Entry point:
60, BE, 00, C0, 49, 00, 8D, BE, 00, 50, F6, FF, C7, 87, 10, 17, 0B, 00, 65, 17, 51, F0, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8524

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
444 KB (454,656 bytes)

Remove whitesmokeinstaller_9147.exe - Powered by Reason Core Security