whitesmokeinstaller_9481.exe

InstallCore© Installer

WhiteSmoke Inc

The application whitesmokeinstaller_9481.exe, “InstallCore© Installer” by WhiteSmoke Inc has been detected as adware by 14 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
InstallCore ©  (signed by WhiteSmoke Inc)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1.0.0.8

MD5:
3ede6c6e27538cf9b0967feb989145fa

SHA-1:
405cb3e008a1faa645b1e150edb569fa9797c9fe

SHA-256:
cb63dce1780a04d60e3229792892a3bd9fa427da14af6d724d3966ba6f727752

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 1:11:32 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.206.214

avast!
Win32:InstallCore-BA [PUP]
2014.9-151202

AVG
Generic
2016.0.2908

Comodo Security
Heur.Suspicious
20953

Dr.Web
Adware.InstallCore.3
9.0.1.0336

ESET NOD32
Win32/InstallCore.K potentially unwanted (variant)
9.11119

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

G Data
Win32.Application.Dealply
15.12.25

Malwarebytes
Adware.Agent
v2015.12.02.11

Reason Heuristics
PUP.WhiteSmoke.InstallCoreC.Installer (M)
15.12.2.11

Sophos
Install Core Installer
4.98

Vba32 AntiVirus
AdWare.WhiteSmoke
3.12.26.3

ViRobot
Trojan.Win32.A.Agent.530256[UPX][h]
2014.3.20.0

Zillya! Antivirus
Adware.WhiteSmoke.Win32.2731
2.0.0.2052

File size:
444.8 KB (455,504 bytes)

Product version:
1, 0, 0, 9

Copyright:
five stars

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
6/29/2011 2:00:00 AM

Valid to:
7/8/2013 1:59:59 AM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64048D72F9FFEF12A43FC4F4CEA580E3

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:IzSmXRVP6q+xwmuTaTseZeIGj23OW8wVlbBbMMq7:IFB56q+xwmueTsr28mbBbMMq7

Entry address:
0xFA910

Entry point:
60, BE, 00, 50, 49, 00, 8D, BE, 00, C0, F6, FF, C7, 87, 10, 17, 0B, 00, 62, E2, CC, 72, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
408 KB (417,792 bytes)

Remove whitesmokeinstaller_9481.exe - Powered by Reason Core Security