adlsoft_uncompressor.exe

ADLSoft

The application adlsoft_uncompressor.exe by ADLSoft has been detected as adware by 14 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from s3.amazonaws.com.
Publisher:
ADLSoft  (signed and verified)

MD5:
5dfe135d43be3475359d1632921b84f7

SHA-1:
33605260b46a32a1120be49a32683ab13554bba7

SHA-256:
335abbf2f7a85da02223962a7dc9586203750095d0dbae4c0b205967010af89c

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Uses the InstallCore download and install manager which may bundle various potentially unwanted software offers during setup.

Analysis date:
12/24/2024 5:05:16 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.InstallCore
2013.06.27

Avira AntiVirus
7.11.87.40

Comodo Security
UnclassifiedMalware
16498

Dr.Web
Adware.InstallCore.38
9.0.1.0230

ESET NOD32
Win32/InstallCore.BP (variant)
8.8492

Fortinet FortiGate
W32/InstallCore.A
8/18/2014

F-Prot
W32/InstallCore.G.gen
v6.4.7.1.166

Malwarebytes
Adware.Agent
v2014.08.18.11

Quick Heal
Trojan.InstallCore.a
8.14.12.00

Reason Heuristics
PUP.ADLSoft.U
14.8.18.11

Sophos
Install Core Installer
4.90

SUPERAntiSpyware
Adware.InstallCore
10414

Total Defense
Win32/InstallCore!Adware
37.0.10483

Vba32 AntiVirus
Adware.InstallCore.gen
3.12.22.2

File size:
557.5 KB (570,888 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\adlsoft_uncompressor.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/22/2011 2:00:00 AM

Valid to:
7/26/2012 1:59:59 AM

Subject:
CN=ADLSoft, O=ADLSoft, L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
522DE3F48188350D9BEBAD2434E15998

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4s/gdlfWq93pzidIEsjnT4KVcjANTfWSROlKKGQn0:4s4d593Qd7ansKTlbwyQn0

Entry address:
0x116200

Entry point:
60, BE, 00, 30, 49, 00, 8D, BE, 00, E0, F6, FF, C7, 87, 10, B7, 0C, 00, F2, 14, 48, D8, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
528 KB (540,672 bytes)

The file adlsoft_uncompressor.exe has been seen being distributed by the following URL.

Remove adlsoft_uncompressor.exe - Powered by Reason Core Security