facemoods.exe

InstallCore© Installer

Volonet Ltd

The application facemoods.exe, “InstallCore© Installer” by Volonet has been detected as adware by 8 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from i.facemoods.com.
Publisher:
InstallCore ©  (signed by Volonet Ltd)

Product:
InstallCore© Installer

Description:
InstallCore© Installer

Version:
1, 0, 0, 9

MD5:
59543527521275b13ab6afd6aa350ca7

SHA-1:
32db96e958843e52094890676f9d46fd910afcca

SHA-256:
64564a11cac6509b631c5bf33a447b92c671d97a7e0fb03bc3bafb6b141e0dfb

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 12:43:16 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
7.11.88.10

avast!
Win32:InstallCore-BA [PUP]
2014.9-150116

Comodo Security
Heur.Suspicious
16523

Dr.Web
Adware.Funmoods.3
9.0.1.016

ESET NOD32
Win32/SweetIM (variant)
9.8510

F-Prot
W32/InstallCore.I2.gen
v6.4.7.1.166

Reason Heuristics
PUP.Installer.Volonet.M
15.1.16.8

Trend Micro House Call
TROJ_GEN.F47V0821
7.2.16

File size:
379.7 KB (388,824 bytes)

Product version:
1, 0, 0, 9

Copyright:
Copyright © InstallCore

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\facemoods.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/24/2010 2:00:00 AM

Valid to:
11/24/2012 1:59:59 AM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel-Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
27228002C4368B8985B0D57BC7FE75CC

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:BPuZGmtr8rrnIPU6IN9+FVOpBozE0fHbdTTj4mUlNTtIV3guXjrIrEik:BPuZGmtUISCFVm6E0fHbdTT0mWNqHIra

Entry address:
0xE1CC0

Entry point:
60, BE, 00, E0, 48, 00, 8D, BE, 00, 30, F7, FF, C7, 87, 10, 57, 0A, 00, 3A, 50, B8, 9D, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
336 KB (344,064 bytes)

The file facemoods.exe has been seen being distributed by the following URL.

Remove facemoods.exe - Powered by Reason Core Security