wordtopdf_setup1.exe

Freeware Solutions

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application wordtopdf_setup1.exe by Freeware Solutions has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the installCore installer. This file is typically installed with the program Free Word To PDF by freepdfsolutions.com. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Freeware Solutions  (signed and verified)

MD5:
59bce6a94edb264ed090db51a5d60ae7

SHA-1:
d741c85bbc6b24b9ebb898dc79d8255e76da5361

SHA-256:
f7dbece238f59745b9189602aaec00e30761bb6efc2c5d0bd76a7b4ff78ab026

Scanner detections:
2 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 9:31:51 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.QF (variant)
8.10828

Reason Heuristics
PUP.Installer.installCore
15.2.14.11

File size:
774.3 KB (792,904 bytes)

Product version:
1.5

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\wordtopdf_setup1.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/16/2014 4:00:00 PM

Valid to:
11/18/2015 4:00:00 AM

Subject:
CN=Freeware Solutions, O=Freeware Solutions, L=Seattle, S=Washington, C=US

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0A94A44D7737D1F4360442DAB8E1836C

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:JwvpOtgMEzFIw/ftD8jaP/Wj6xF346f0iMiKPW7YMx45yABrZUzvzBpb0Z:JwvQCxnSkejwF346fMUYMeBF6DG

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8468

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file wordtopdf_setup1.exe has been discovered within the following program.

Free Word To PDF  by freepdfsolutions.com
Publisher's description - “Convert all your .pdf files to .JPG files and more. This software is free and makes it very easy for all your needs.”
www.freepdfsolutions.com
45% remove it
 
Powered by Should I Remove It?

The file wordtopdf_setup1.exe has been seen being distributed by the following 25 URLs.

http://global-shared-files-l3.softonic.com/d74/1c8/.../file?nvb=20141128091604&nva=20141128211704&token=0ffda79c342aa1b7d0595&instance=softonic_en&filename=wordtopdf_setup1.exe

http://global-shared-files-l3.softonic.com/d74/1c8/.../file?nvb=20150104191433&nva=20150105071533&token=0208d28f5b11ad10e63bd&SD_used=0&channel=WEB&fdh=no&id_file=69669343&instance=softonic_en&type=PROGRAM&filename=wordtopdf_setup1.exe

http://global-shared-files-l3.softonic.com/d74/1c8/.../file?nvb=20150104191534&nva=20150105071634&token=04c0bb4881fc21e50b10c&SD_used=0&channel=WEB&fdh=no&id_file=69669343&instance=softonic_en&type=PROGRAM&filename=wordtopdf_setup1.exe

http://dc725.4shared.com/download/.../wordtopdf_setup1.exe

http://global-shared-files-l3.softonic.com/d74/1c8/.../file?nvb=20150105190747&nva=20150106070847&token=0aabae29fa38132783dbb&SD_used=0&channel=WEB&fdh=no&id_file=69669343&instance=softonic_en&type=PROGRAM&filename=wordtopdf_setup1.exe

http://global-shared-files-l3.softonic.com/d74/1c8/.../file?nvb=20141230113452&nva=20141230233552&token=0a040acb59f03a8d34cb6&SD_used=0&channel=WEB&fdh=no&id_file=69669343&instance=softonic_en&type=PROGRAM&filename=wordtopdf_setup1.exe

http://global-shared-files-l3.softonic.com/d74/1c8/.../file?nvb=20150102215838&nva=20150103095938&token=0a53ea07df0cd2849702b&SD_used=0&channel=WEB&fdh=no&id_file=69669343&instance=softonic_en&type=PROGRAM&filename=wordtopdf_setup1.exe

Remove wordtopdf_setup1.exe - Powered by Reason Core Security