wotweboftrustforinternetexplorer-setup.exe

Web Install

This installer uses the CNET Download.com download manager (private label) in order to provide monetized offerings to end users. These offers could include ad-supported toolbars or various web browser extensions. The application wotweboftrustforinternetexplorer-setup.exe by Web Install has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the DownloadCom Spot Install installer. With this installer, users are expecting to download Internet Explorer but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Web Install  (signed and verified)

MD5:
43377c026b6cfedd3cb9c0b03fb2ef42

SHA-1:
fad8cc51d12a361dc4ceaca4ad12f39797a7bd8a

SHA-256:
24885f563846815ade9b0cbdca68f0e629443b8ffd42a7978c62893a1ca179f0

Scanner detections:
7 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 3:09:38 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Adware-BGE [PUP]
2014.9-140919

Dr.Web
Adware.Downware.1159
9.0.1.0262

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
8.7.0.302.0

herdProtect (fuzzy)
2014.11.30.7

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.59921

Reason Heuristics
PUP.Installer.WebInstall.g
14.9.19.19

VIPRE Antivirus
Threat.4782786
29418

File size:
641.5 KB (656,864 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
DownloadCom Spot Install (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\wotweboftrustforinternetexplorer-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/19/2013 5:00:00 PM

Valid to:
3/19/2016 4:59:59 PM

Subject:
CN=Web Install, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Web Install, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6F93708E2A9DB00DA7666A9EA9A5FA00

File PE Metadata
Compilation timestamp:
6/22/2012 11:07:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:XXNRmR4TUPiaOP/SYG25CHFpJfMwp71q4OVNx6fRWH5GuP:XX44UDOS20vtMwZ1BENx8WZh

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.9446

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove wotweboftrustforinternetexplorer-setup.exe - Powered by Reason Core Security