installmanager.exe

The application installmanager.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from secure.fordcdnsecure.com.
MD5:
a579b1ab94fa9cece41c57ceceb9a067

SHA-1:
bbd86f839d626ac1549ac5c8a16ab3941b56f30f

SHA-256:
3275a56f4f826011a608f9e0f6c2fe823a70486f086983ccc4fc8ab2696b1d0b

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
12/25/2024 1:19:56 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.195.56

Baidu Antivirus
PUA.Win32.VMDetector
4.0.3.141221

Dr.Web
Adware.Downware.918
9.0.1.0355

ESET NOD32
Win32/InstallMonetizer.BD
8.10873

Malwarebytes
Riskware.Vmdetector
v2014.12.21.03

NANO AntiVirus
Trojan.Nsis.Downloader.djhpgw
0.28.6.63850

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.141219

SUPERAntiSpyware
Adware.InstallMonetizer
10165

File size:
323.6 KB (331,345 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\installmanager.exe

File PE Metadata
Compilation timestamp:
12/6/2009 1:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:1FJ0SUl+0WC8oD7pJ59ECadigTZXwVCTtZ4rt5q2pd5A8WwFi:JGFH8k7pBAdZXwVC/4rbJd5A8I

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9077

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installmanager.exe has been seen being distributed by the following URL.

Remove installmanager.exe - Powered by Reason Core Security