facemoods.exe

Volonet Ltd

The application facemoods.exe, “Powered by InstallCore” by Volonet has been detected as adware by 10 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from i.facemoods.com.
Publisher:
Facemoods  (signed by Volonet Ltd)

Product:
Facemoods

Description:
Powered by InstallCore

Version:
2.0.1.73

MD5:
747aeb0c751778c95dc3122a6eb199ab

SHA-1:
4c2dd61121e88d5df98fd8a1a71d631ae6688b69

SHA-256:
cd90c2ffc58614d6ea7e0918d2e18f216a80a5f0e1de1bc395530be07be6c960

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/6/2024 12:55:03 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Adware/Win32.FoxTab
2013.03.22

avast!
Win32:PUP-gen [PUP]
2014.9-140920

Dr.Web
Adware.Funmoods.3
9.0.1.0263

Emsisoft Anti-Malware
Application.InstallCore.AW
8.14.09.20.12

ESET NOD32
Win32/InstallCore (variant)
8.8148

NANO AntiVirus
Riskware.Win32.InstallCore.nxzhi
0.22.8.51404

Reason Heuristics
PUP.Installer.Volonet.J
14.9.20.12

SUPERAntiSpyware
Trojan.Agent/Gen-Falleg[Cont]
10348

Trend Micro House Call
TROJ_GEN.RCBH1KM
7.2.263

Vba32 AntiVirus
BScope.Malware-Cryptor.Sinba.A
3.12.20.2

File size:
555.7 KB (569,048 bytes)

Product version:
2.0.1.73

Copyright:
Copyright © Instsaller

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\facemoods.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
11/24/2010 12:00:00 AM

Valid to:
11/23/2012 11:59:59 PM

Subject:
CN=Volonet Ltd, O=Volonet Ltd, STREET=hazfira 19, L=Tel-Aviv, S=Israel, PostalCode=67778, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
27228002C4368B8985B0D57BC7FE75CC

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:IK44k+DkT6rGnxTVNBmbmYGxGNYIOmDHamzpoh8ah07Y3YgG1XO:I4yTmCxlhez6m6Ga67YoL1XO

Entry address:
0x1363F0

Entry point:
60, BE, 00, B0, 4B, 00, 8D, BE, 00, 60, F4, FF, C7, 87, 10, E7, 0B, 00, 7A, 44, F3, 01, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.7960

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
496 KB (507,904 bytes)

The file facemoods.exe has been seen being distributed by the following URL.

Remove facemoods.exe - Powered by Reason Core Security