izarc_setup.exe

Creative Internet Ltd

The application izarc_setup.exe by Creative Internet has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from download.downloadhosters.com.
Publisher:
Creative Internet Ltd  (signed and verified)

MD5:
953d9e35d401e23265384feaafeb72ed

SHA-1:
25e2dd45f93aa42c4a5f2a342dde8498e00fbbb8

SHA-256:
a665552ccfe0eb1f56d17e8d65b99d385ce3a52386a3f8f45c6537e6e9b476aa

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 9:27:56 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore (M)
16.11.10.3

File size:
624.5 KB (639,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\izarc_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/15/2013 1:00:00 AM

Valid to:
8/16/2014 12:59:59 AM

Subject:
CN=Creative Internet Ltd, O=Creative Internet Ltd, STREET=64 SOUTHWARK BRIDGE ROAD, L=SOUTHWARK, S=London, PostalCode=SE1 0AS, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B0260B1A6AF7BB022FE065132251B61D

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4oMJfsGN9wy8sxzin+yAcJJgq0ydbkA5Ew4LlKVJaEdjQB0dL9X+upd:fMJfsAGy8uin+DcJW7yJQlGwF0t9X

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8242

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file izarc_setup.exe has been seen being distributed by the following URL.

http://download.downloadhosters.com/download/izarc.downloadhosters.com/.../IZArc_Setup.exe

Remove izarc_setup.exe - Powered by Reason Core Security