radarsync.exe

RadarSync

The application radarsync.exe by RadarSync has been detected as a potentially unwanted program by 10 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
RadarSync  (signed and verified)

MD5:
5121763dc9d3d5aec31959a03c6c3518

SHA-1:
3bb894c311ea5c9b124247d5324b13fa33cbb0d0

SHA-256:
bc80f2b5a19382c4e3c36732b6c1603ea815adce1c2a38f07a575de58719d3ad

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 7:27:41 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2013.01.18

Avira AntiVirus
7.11.57.194

Clam AntiVirus
W32.Adware.InstallCore-1
0.98/18155

Dr.Web
Adware.InstallCore.43
9.0.1.038

Emsisoft Anti-Malware
Adware.Generic.264671
8.15.02.07.10

ESET NOD32
Win32/InstallCore (variant)
9.7905

F-Prot
W32/InstallCore.G.gen
v6.4.6.5.141

K7 AntiVirus
Unwanted-Program
13.158.8121

Trend Micro House Call
TROJ_GEN.RCEH1GC
7.2.38

Vba32 AntiVirus
Malware-Cryptor.InstallCore.8
3.12.18.4

File size:
1003 KB (1,027,088 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
8/16/2011 2:00:00 AM

Valid to:
5/20/2012 1:59:59 AM

Subject:
CN=RadarSync, O=RadarSync, L=Highland Park, S=Illinois, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
21C0A661B6DC7A88F376DB8C90E62175

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:0iqVXYM1TglBtWS3Gr8R1uCa8BDHj3qZJBGqw4VOqQCAqD3AcPlf0hNbtbzMPRlA:0iM5nQuGZH2ZJB/wQO/4DPPuRbwPRmOo

Entry address:
0xC1BA8

Entry point:
55, 8B, EC, 83, C4, F0, B8, 61, BC, 47, 00, E8, E6, F9, FF, FF, 44, 60, 40, 00, 8C, 37, 40, 00, 80, 37, 40, 00, 54, 60, 40, 00, E4, 34, 40, 00, 20, 35, 40, 00, 11, 54, 49, 6E, 74, 65, 72, 66, 61, 63, 65, 64, 4F, 62, 6A, 65, 63, 74, 8B, C0, 1C, 12, 40, 00, 11, 0B, 54, 42, 6F, 75, 6E, 64, 41, 72, 72, 61, 79, 04, 00, 00, 00, 00, 00, 00, 00, 03, 00, 00, 00, 54, 10, 40, 00, 06, 53, 79, 73, 74, 65, 6D, FF, 25, E0, 31, 47, 00, 8B, C0, FF, 25, DC, 31, 47, 00, 8B, C0, FF, 25, D8, 31, 47, 00, 8B, C0, FF, 25, D4, 31...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
787 KB (805,888 bytes)

Remove radarsync.exe - Powered by Reason Core Security