download.exe

MinWare

Ivan Kostin

This program bundles adware during the download and install process using the InstaleRex pay-per-install app monetizer. The application download.exe, “Installer for MinWare” by Ivan Kostin has been detected as adware by 35 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
House Of Soft  (signed by Ivan Kostin)

Product:
MinWare

Description:
Installer for MinWare

Version:
2014.1.13.1606

MD5:
d2fdd3c49179ee0f25732f362a77d7e3

SHA-1:
d50b9df2d2f06a4a9d0b181df13b0d988fa26cd7

SHA-256:
64b4d88e4d76a95b600940e5ed1505072a264fad39f4552114acfd4fde3bc1c0

Scanner detections:
35 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
12/27/2024 3:00:45 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.10396428
1107

Agnitum Outpost
PUA.InstalleRex
7.1.1

AhnLab V3 Security
PUP/Win32.TSULoader
2014.01.24

Avira AntiVirus
Adware/InstallRex.X
7.11.126.198

avast!
Win32:InstalleRex-AI [PUP]
2014.9-140123

AVG
MalSign.Generic
2015.0.3585

Bitdefender
Trojan.Generic.10396428
1.0.20.115

Bkav FE
HW32.CDB
1.3.0.4959

Clam AntiVirus
Win.Trojan.Installerex-25
0.98/19168

Comodo Security
Application.Win32.InstalleRex.KG
17662

Dr.Web
Adware.Downware.1541
9.0.1.023

Emsisoft Anti-Malware
Trojan.Generic.10396428
8.14.01.23.01

ESET NOD32
Win32/InstalleRex
8.9329

Fortinet FortiGate
Riskware/InstalleRex
1/23/2014

F-Prot
W32/InstallRex.B.gen
v6.4.7.1.166

F-Secure
Trojan.Generic.10396428
11.2014-23-01_5

G Data
Trojan.Generic.10396428
14.1.24

herdProtect (fuzzy)
2014.1.27.0

IKARUS anti.virus
PUP.InstallRex
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.178.12292

Kaspersky
not-a-virus:Downloader.Win32.AdLoad
14.0.0.4422

Malwarebytes
PUP.Optional.Installrex
v2014.01.23.01

McAfee
PUP-FHQ!1F4116E31906
5600.7045

MicroWorld eScan
Trojan.Generic.10396428
15.0.0.69

NANO AntiVirus
Riskware.Win32.Downware.ctkpgl
0.28.0.58720

nProtect
Trojan.Generic.10396428
14.01.23.02

Panda Antivirus
Adware/TSUploader
14.01.23.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Quick Heal
Trojan.AntiFW.A5
8.14.14.00

Reason Heuristics
Adware.WebPick.Installer.I
14.8.8.0

Rising Antivirus
PE:PUF.InstallRex!1.9E4C
23.00.65.14121

Sophos
InstallRex
4.97

Vba32 AntiVirus
Downloader.AdLoad
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
25728

Zillya! Antivirus
Downloader.Adload.Win32.16992
2.0.0.1837

File size:
313.1 KB (320,640 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © 2014 House Of Soft

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Common path:
C:\users\{user}\downloads\download.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/25/2013 8:00:00 AM

Valid to:
8/26/2014 7:59:59 AM

Subject:
CN=Ivan Kostin, O=Ivan Kostin, STREET=Pobedy 33/1, L=Kyiv, S=Kyiv, PostalCode=03170, C=UA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EB11D24CE6DDBBF752FE4DC3D683D2BF

File PE Metadata
Compilation timestamp:
3/12/2013 4:51:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:7rq9uEo2S1YnQmCX492DkwNP3qpYFFSvzUIHZd0uzymaeMrreEsQRj1:7rSu6/eIo41QIHZGBJKWj1

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9512

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file download.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

Remove download.exe - Powered by Reason Core Security