facemoods.exe

InstallCore© Installer

Volonet Ltd

The application facemoods.exe, “InstallCore© Installer” by Volonet has been detected as adware by 9 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from i.facemoods.com.
Publisher:
InstallCore ©  (signed by Volonet Ltd)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1, 0, 0, 9

MD5:
f01ccf479b11d953b93298efb9bebc91

SHA-1:
20d4414c399aab10065d4d4c6a75ea43b6a7867d

SHA-256:
15c64a6af1489d920ebd6e382218c4c60f16e19273f5f905ad5302f46c85e6c5

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 12:27:19 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.154.68

avast!
Win32:InstallCore-BA [PUP]
2014.9-140629

AVG
Generic
2015.0.3429

Comodo Security
Heur.Suspicious
18505

Dr.Web
Adware.Funmoods.3
9.0.1.0180

ESET NOD32
Win32/SweetIM (variant)
8.9925

Fortinet FortiGate
Riskware/SweetIM
6/29/2014

F-Prot
W32/InstallCore.I.gen
v6.4.7.1.166

Reason Heuristics
PUP.Installer.Volonet.J
14.8.7.21

File size:
379.7 KB (388,824 bytes)

Product version:
1, 0, 0, 9

Copyright:
Copyright © InstallCore

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\facemoods.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/23/2010 6:00:00 PM

Valid to:
11/23/2012 5:59:59 PM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel-Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
27228002C4368B8985B0D57BC7FE75CC

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:vPuZGmtr8rrnIPU6IN9+FVOpBozE0fHbdTTj4mUlNTt77H9EqriPvv/OYiZ:vPuZGmtUISCFVm6E0fHbdTT0mWNN7vGA

Entry address:
0xE1CC0

Entry point:
60, BE, 00, E0, 48, 00, 8D, BE, 00, 30, F7, FF, C7, 87, 10, 57, 0A, 00, 3A, 50, B8, 9D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.7641

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
336 KB (344,064 bytes)

The file facemoods.exe has been seen being distributed by the following URL.

Remove facemoods.exe - Powered by Reason Core Security