flvinstaller.exe

SafeInstaller

SecureInstall, LLC

This is the InstallX/InstallIQ download manager and installer that will bundle offers during setup for additional PUPs and other unwanted software. The application flvinstaller.exe by SecureInstall has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the InstallIQ Installation Manager installer. It is also typically executed from the user's temporary directory.
Publisher:
SafeInstall, LLC  (signed by SecureInstall, LLC)

Product:
SafeInstaller

Description:
Safe Installer

Version:
1.0.30.0

MD5:
b1f5a759781f1599def6355593ef4779

SHA-1:
87e6883990ce712a4def85dac81da8f45f156bda

SHA-256:
28cc5fde88e74736c62cc5576eb4106c45f152a6466837143d55ea605d43ee0b

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Uses the InstallIQ (by InstallX) software bundler that may include toolbars and other browser extensions offers.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
1/12/2025 10:45:24 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

avast!
PUP-gen [PUP]
2014.9-140808

AVG
MultiBundle
2015.0.3556

Dr.Web
Adware.Searcher.2593
9.0.1.052

Emsisoft Anti-Malware
Adware.Generic.380224
8.14.02.21.05

ESET NOD32
Win32/InstallIQ (variant)
8.9453

G Data
Win32.Application.InstallIQ
14.8.24

K7 AntiVirus
Unwanted-Program
13.177.11935

Malwarebytes
PUP.Optional.SafeInstall.A
v2014.02.21.05

McAfee
Artemis!B1F5A759781F
5600.7212

NANO AntiVirus
Trojan.Win32.Searcher.csnymk
0.28.0.57630

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.SecureInstall.M
14.8.8.0

Rising Antivirus
PE:PUF.InstallIQ!1.9E4F
23.00.65.14219

Sophos
DomainIQ pay-per install
4.97

Trend Micro House Call
ADW_INSTALLIQ
7.2.220

Trend Micro
ADW_INSTALLIQ
10.465.08

VIPRE Antivirus
InstallIQ Installer
26682

XVirus List
Win32.Detected
2.4.14

File size:
1.6 MB (1,709,160 bytes)

Product version:
1.0.30.0

Copyright:
Copyright (C) 2014

Original file name:
safeinstall.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallIQ Installation Manager

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\flvinstaller.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
11/19/2013 2:00:00 AM

Valid to:
11/24/2014 2:00:00 PM

Subject:
CN="SecureInstall, LLC", O="SecureInstall, LLC", L=Sartell, S=Minnesota, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
073E5B30FA98352DDA4DA1FD7215A72F

File PE Metadata
Compilation timestamp:
2/19/2014 8:11:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:bYmq3HplWsv2PhscqWzBvqeVR9Vo1bb8MnaG9kIueboeBT7sAzUrTmksThlenfCS:7ZLr1qhFnNk9uoe9zUvsTECwhuYqwl

Entry address:
0x4DE9D

Entry point:
E8, F0, 3A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, B0, 69, 52, 00, E8, 2D, 2B, 00, 00, E8, BD, 3C, 00, 00, 0F, B7, F0, 6A, 02, E8, 83, 3A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 64, 34, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.9704

Code size:
974.5 KB (997,888 bytes)

Remove flvinstaller.exe - Powered by Reason Core Security