include.exe

Amazing Software Products

The application include.exe, “Advanced Searchbar for Windows” by Amazing Software Products has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Wise Installer installer. Additionally, the file is typically installed by a number of programs including Talking Buddy for Windows by Talking Buddy and Optimize Memory for Windows by Optimize Memory for Windows. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Advanced Searchbar for Windows  (signed by Amazing Software Products)

Description:
Advanced Searchbar for Windows

Version:
3.21

MD5:
e8ab9d88c81993916cecc3995b8d98e0

SHA-1:
9e4a1931739b3ca2cd80ed367bb86c2046278982

SHA-256:
16402c303286c23a19504deab6285a9c1102da5abd4db08b98b02127e7adce13

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/13/2025 2:48:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AmazingS (M)
16.5.12.12

File size:
975.7 KB (999,072 bytes)

Copyright:
2005

File type:
Executable application (Win32 EXE)

Installer:
Wise Installer

Language:
English (United States)

Common path:
C:\Program Files\weberaser\include.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/5/2004 5:30:00 AM

Valid to:
11/6/2005 5:29:59 AM

Subject:
CN=Amazing Software Products, OU=Amazing Software Products, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Amazing Software Products, L=Wilmington, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
516687062D755A0A7A1294F79BE062DA

File PE Metadata
Compilation timestamp:
4/9/1999 1:54:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:9kowFYOvy1LTYBW5QAILOzYZ5pSrbWni+i:9kowswBpAILOkZ5pCCnw

Entry address:
0x1000

Entry point:
55, 8B, EC, 81, EC, 78, 05, 00, 00, 53, 56, BE, 04, 01, 00, 00, 57, 8D, 85, 94, FD, FF, FF, 56, 33, DB, 50, 53, FF, 15, 34, 20, 40, 00, 8D, 85, 94, FD, FF, FF, 56, 50, 8D, 85, 94, FD, FF, FF, 50, FF, 15, 30, 20, 40, 00, 8B, 3D, 2C, 20, 40, 00, 53, 53, 6A, 03, 53, 6A, 01, 8D, 85, 94, FD, FF, FF, 68, 00, 00, 00, 80, 50, FF, D7, 83, F8, FF, 89, 45, FC, 0F, 84, 7B, 01, 00, 00, 8D, 85, 90, FC, FF, FF, 50, 56, FF, 15, 28, 20, 40, 00, 8D, 85, 98, FE, FF, FF, 50, 53, 8D, 85, 90, FC, FF, FF, 68, 10, 30, 40, 00, 50...
 
[+]

Entropy:
7.9900

Packer / compiler:
Wise Installer Stub

Code size:
512 Bytes (512 bytes)

The file include.exe has been discovered within the following programs.

Optimize Memory for Windows  by Optimize Memory for Windows
www.optimizememory.com
57% remove it
Talking Buddy for Windows  by Talking Buddy
About 2% of users remove it
 
Powered by Should I Remove It?

Remove include.exe - Powered by Reason Core Security