installer.exe

Downloadcentral ApS

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application installer.exe by Downloadcentral ApS has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.downloadcentral.dk.
Publisher:
Downloadcentral ApS  (signed and verified)

MD5:
fe908113d284ff4a708c5a250d2a9ce0

SHA-1:
a55d8b34d12fcfa9d3197998cadb1e1997c00369

SHA-256:
5f620b9b160d03d8cd3b2e79576fb397c0d577735e325fa0ffad98a4c90bdde4

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/5/2024 6:48:00 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.InstallCore.80
9.0.1.05190

Emsisoft Anti-Malware
Adware.Generic.546916
10.0.0.5366

ESET NOD32
Win32/InstallCore.AZ potentially unwanted application
8.0.319.0

F-Prot
W32/InstallCore.S.gen
4.6.5.141

Norman
Adware.Generic.546916
19.02.2016 10:08:15

Reason Heuristics
PUP.installCore.Downloadcentral (M)
16.2.22.10

VIPRE Antivirus
Threat.4788237
47238

File size:
1.1 MB (1,205,376 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\users\{user}\downloads\installer.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/10/2012 12:00:00 AM

Valid to:
7/10/2013 11:59:59 PM

Subject:
CN=Downloadcentral ApS, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Downloadcentral ApS, L=Odense, S=Odense, C=DK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3E0CD42145109655AB37716301DF2ABC

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:iHLbvDG2oGSZ8BwPCfZabMdt8kAphvCwGvT6zu7TeAX6nRp8:IvDG5sc2IryT6m/X6

Entry address:
0xD6620

Entry point:
55, 8B, EC, 83, C4, F0, B8, D8, 24, 41, 00, E8, 3E, E3, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
869.5 KB (890,368 bytes)

The file installer.exe has been seen being distributed by the following URL.

Remove installer.exe - Powered by Reason Core Security