installer-zip-2.exe

nuevos-programas.com Downloader

Cpc Net Advertising LLC

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application installer-zip-2.exe by Cpc Net Advertising has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer.
Publisher:
Cpc Net Advertising LLC  (signed and verified)

Product:
nuevos-programas.com Downloader

Version:
1.0.5.51163

MD5:
f2aaa7ef1cf5beaa8a80c015294fac9a

SHA-1:
0ea6629b2cb20d3167ee1a5633dc27361899ddb7

SHA-256:
1291efbfa248bd392c60ece33cfccb98475c20e9652d46ffe000bd0081dfe386

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
2/26/2025 8:46:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.2.8.1

File size:
984.6 KB (1,008,200 bytes)

Product version:
1.0.5.51163

Original file name:
ClickOnceSetup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\installer-zip-2.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
7/1/2015 2:00:00 AM

Valid to:
7/1/2016 1:59:59 AM

Subject:
CN=Cpc Net Advertising LLC, OU=IT, O=Cpc Net Advertising LLC, L=Wilmington, S=Delaware, C=US

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2BC1DD7AA35DE89A0D5276ECD7AE32AF

File PE Metadata
Compilation timestamp:
1/16/2016 11:35:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0xEE43E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
945.5 KB (968,192 bytes)

Remove installer-zip-2.exe - Powered by Reason Core Security