spellcheckstub64.exe

Spellology

InstallX, LLC

Part of an InstallX (InstallIQ) installation, a PUP that may bundle additional adware on the computer. The application spellcheckstub64.exe by InstallX has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Spellology by InstallX, LLC which is a potentially unwanted software program.
Publisher:
InstallX, LLC  (signed and verified)

Product:
Spellology

Description:
Spellology Stub

Version:
1.0.6.0

MD5:
419cdba325c68bccfd04859f5b095c35

SHA-1:
51bdaad6addc372ef19ceadc51973f1376b9f109

SHA-256:
39bffcaa1b814054058f0208704a899abf87273d03a8e6f6443cc06b353a4230

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/22/2024 5:06:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallX (M)
17.3.9.15

File size:
181 KB (185,376 bytes)

Product version:
1.0.6.0

Copyright:
Copyright ©2013 InstallX, LLC. All rights reserved.

Original file name:
Spellology

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\spellology\spellcheckstub64.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
3/21/2013 8:00:00 PM

Valid to:
3/26/2014 8:00:00 AM

Subject:
CN="InstallX, LLC", O="InstallX, LLC", L=Sartell, S=Minnesota, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
030985B5A39F75A13A497DAB8BF611F7

File PE Metadata
Compilation timestamp:
10/23/2013 4:28:47 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x2B08

Entry point:
48, 83, EC, 28, E8, FF, 55, 00, 00, 48, 83, C4, 28, E9, 02, 00, 00, 00, CC, CC, 48, 89, 5C, 24, 10, 48, 89, 74, 24, 18, 57, 48, 83, EC, 30, E8, 44, 59, 00, 00, 0F, B7, F0, B9, 02, 00, 00, 00, E8, 8B, 55, 00, 00, B8, 4D, 5A, 00, 00, 48, 8D, 3D, B7, D4, FF, FF, 66, 39, 05, B0, D4, FF, FF, 74, 04, 33, DB, EB, 31, 48, 63, 05, DF, D4, FF, FF, 48, 03, C7, 81, 38, 50, 45, 00, 00, 75, EA, B9, 0B, 02, 00, 00, 66, 39, 48, 18, 75, DF, 33, DB, 83, B8, 84, 00, 00, 00, 0E, 76, 09, 39, 98, F8, 00, 00, 00, 0F, 95, C3, 89...
 
[+]

Entropy:
5.8331

Code size:
100 KB (102,400 bytes)

The file spellcheckstub64.exe has been discovered within the following program.

Spellology  by InstallX, LLC
Spellogy utilizes InstallIQ, which manages the installation. Additional software may be offered to you during the installation process. " InstallIQ™ is an install manager that will manage the installation of your selected software.
www.installiqlearnmore.com
About 58% of users remove it
 
Powered by Should I Remove It?

Remove spellcheckstub64.exe - Powered by Reason Core Security