Install Core Installer

Category: Adware and PUAs Protection available since:07 Nov 2012 23:32:26 (GMT)
Type: Unspecified PUA Last Updated:03 Jul 2013 16:10:43 (GMT)

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

"Install Core Installer" is an installer which bundles legitimate applications with offers for additional third party applications that may be unwanted by the user. Such third party applications are typically installed onto users’ computers by default, but may include an option to ‘opt-out’ during or after the installation process.

Examples of Install Core Installer include:

Example 1

File Information

Size
577K
SHA-1
000121fe9c537b03033fc6d2340114d1331380e8
MD5
28ce3fa1cfea51ac0305cb9855c8fe4c
CRC-32
e060eb04
File type
Windows executable
First seen
2012-07-12

Runtime Analysis

Registry Keys Modified
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    Name
    test_item.exe
HTTP Requests
  • http://cdneu.webfilescdn.com/Prod/FLVPlayer-v2.cis
  • http://cdnus.webfilescdn.com/Prod/FLVPlayer-v2.cis
DNS Requests
  • cdneu.webfilescdn.com
  • cdnus.webfilescdn.com
  • os.webfilescdn.com

Example 2

File Information

Size
519K
SHA-1
000da0ad742dbacd22ab3e1988c9c22ddca3ae10
MD5
7f659cbc0abebfae646274db114901af
CRC-32
5c742504
File type
Windows executable
First seen
2012-07-18

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\ICReinstall_sample.exe
Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\is1590112554\117869_Setup.CIS
  • c:\Documents and Settings\test user\Desktop\Continue FLV Player Installation.lnk
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\blank.gif
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\finish-button.png
    Size
    2.3K
    SHA-1
    e21be5ea412b4dc02b7d3a61ab3a798946224cae
    MD5
    e37ec66b72996fc3ad929cd068570d4d
    CRC-32
    22eff3aa
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\next-button.png
    Size
    2.4K
    SHA-1
    bb5253c868861ff10fd48dcce1309d847f087e80
    MD5
    274548cb843bb96fcb50a79a2340b22d
    CRC-32
    f817eb1e
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\is1590112554\923313444.cfg
    Size
    236
    SHA-1
    d88993cea2000f9f469cdc9560a1406c3ff86593
    MD5
    eaefaeff2850a30d5c07c6c9a1fa8363
    CRC-32
    43aa53e8
    File type
    Base64 encoded
    First seen
    2012-07-18
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\buttons.css
    Size
    1.2K
    SHA-1
    ff395834bb8ff730b31c1daefc8ff197ce280ad0
    MD5
    a84fee16240de0d25f1b3ec8df25a11c
    CRC-32
    afa9d3f9
    File type
    Cascading Style Sheet
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\main.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\Progress.png
  • c:\Documents and Settings\test user\Local Settings\Temp\is1590112554\822155676.cfg
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\progress-bg.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\sdk-ui\button.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\sdk-ui\browse.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\ie6_main.css
    Size
    1.2K
    SHA-1
    e7488b4b7363b011aa82abbce84f914e3329750a
    MD5
    69b3f7194795871e6eac286439118ddd
    CRC-32
    b67b6418
    File type
    Cascading Style Sheet
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\sdk-ui\checkbox.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\sdk-ui\images\progress-bg.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\sdk-ui\images\button-bg.png
    Size
    131
    SHA-1
    a1615c118fbfa49253d98185eae283f26ea392d7
    MD5
    98b1de48dfa64dc2aa1e52facfbee3b0
    CRC-32
    55349b32
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2011-02-04
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\css\sdk-ui\progress-bar.css
    Size
    632
    SHA-1
    88f079fd001feb2cb302565b87fdb81c8995dd93
    MD5
    8f6a2e09ace79158461b82d74ff6c7fd
    CRC-32
    abef9d5d
    File type
    Cascading Style Sheet
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\icon.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\Bg.gif
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\close_button.png
    Size
    1.4K
    SHA-1
    c173be4937a63672570078b325864c76b28040b8
    MD5
    83487401daf307d6c726a479de1ee6f9
    CRC-32
    6f6bf5ce
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\loader.gif
    Size
    6.2K
    SHA-1
    a2b8147953636de537c66afb06105a3889a55915
    MD5
    85954ea60a946e9c41e33260cee2bbc4
    CRC-32
    a0d5923d
    File type
    Graphic interchange format
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\locale\EN.locale
    Size
    2.4K
    SHA-1
    c4108cb3c4154c28511c71329cc97202024ce962
    MD5
    4c8238a01db1ac103d3e876ab77c02ea
    CRC-32
    edc2e02c
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2012-03-16
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\license.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\next-button-over.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish109234\images\ProgressBar.png
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    Name
    test_item.exe
Registry Keys Modified
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    ID
    0x2a425e19
HTTP Requests
  • http://cdneu.flvplayerpro.net/app/Cmp/FLVPlayer-v2.cis
  • http://cdnus.flvplayerpro.net/app/Cmp/FLVPlayer-v2.cis
DNS Requests
  • cdneu.flvplayerpro.net
  • cdnus.flvplayerpro.net
  • os.flvplayerpro.net

Example 3

File Information

Size
557K
SHA-1
000f9c5628b078477b0340e8eb45844da9895543
MD5
5803cd61485657d3ef4465d26fbf1c29
CRC-32
cdcd41ac
File type
Windows executable
First seen
2012-02-04

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Local Settings\Temp\ICReinstall_sample.exe
Dropped Files
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\defaultOffer\offer_code.dat
    Size
    2.0K
    SHA-1
    fbb0b5dcd2cf4131f2819733d59ad5394f522449
    MD5
    1d89ad332b73d8b7a065a0a9b119779e
    CRC-32
    44e549c9
    File type
    JavaScript
    First seen
    2012-01-01
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\ie6_main.css
    Size
    1.3K
    SHA-1
    e2ceb7a77eeb5570650c0c08a32529892ac40b2a
    MD5
    eb6ece534abd5370e99a5e70b7ac3775
    CRC-32
    263b9eaa
    File type
    Cascading Style Sheet
    First seen
    2011-01-01
  • c:\Documents and Settings\test user\Local Settings\Temp\is1438683437\131593377.cfg
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\back-button.png
    Size
    1.3K
    SHA-1
    b3b4248e492727690c2adc7306a8ea0cd675b2ef
    MD5
    c5d63a3d40ff748895cf763749e8b931
    CRC-32
    153dff79
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2011-01-01
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\Bg.jpg
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\sdk-ui\images\button-bg.png
    Size
    131
    SHA-1
    a1615c118fbfa49253d98185eae283f26ea392d7
    MD5
    98b1de48dfa64dc2aa1e52facfbee3b0
    CRC-32
    55349b32
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2011-02-04
  • c:\Documents and Settings\test user\Desktop\Continue FoxTab Music Converter Installation.lnk
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\main.css
    Size
    3.8K
    SHA-1
    8f2d54747f7e34b16311e435448a32cf23e6abd1
    MD5
    a57feadde7e5a4d66d498841fe67f10b
    CRC-32
    6fa789db
    File type
    Cascading Style Sheet
    First seen
    2011-07-11
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\finish_button.jpg
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\next-button-over.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\loader.gif
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\buttons.css
    Size
    1.2K
    SHA-1
    c3110a2cc7c003c37b9cdb77f57dbd39bc7ae35b
    MD5
    f03b9fcc0266083e3230b560e77a9793
    CRC-32
    2b6fa2ff
    File type
    Cascading Style Sheet
    First seen
    2011-07-11
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\sdk-ui\images\progress-bg.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\next-button.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\defaultOffer\US\offer_code.dat
    Size
    7.6K
    SHA-1
    df923a6f06efb95f8ffc768d99e80cebfadc7b1a
    MD5
    278fc4f3f366776d295797d6e840da33
    CRC-32
    5a2e0d79
    File type
    JavaScript
    First seen
    2012-01-13
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\blank.gif
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\sdk-ui\browse.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\sdk-ui\checkbox.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\close_button.png
    Size
    1.2K
    SHA-1
    b9968e5cb49d8607eca39d1bb77dd6c7ec78ed0b
    MD5
    77804bd31b703f61b2c3de518cd25d38
    CRC-32
    0652477e
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2011-01-01
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\defaultOffer\US\offer_html.dat
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\skip-button.png
    Size
    1.4K
    SHA-1
    fd05f5b1d3f7c22d2e552e5710a87c8377df5e9d
    MD5
    db6ed921d71eb71d0f2e472655163128
    CRC-32
    35e99774
    File type
    PNG (Portable Network Graphics) image format
    First seen
    2011-01-01
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\Software.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\finish-button.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\icon.png
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\license.txt
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\sdk-ui\button.css
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\defaultOffer\offer_html.dat
    Size
    3.0K
    SHA-1
    c7e9492888824ab18630493ed491ab1a12091752
    MD5
    2cfb9e2a6c87aa189dd551214876bed1
    CRC-32
    371cc8a8
    File type
    Unspecified Markup Language
    First seen
    2011-07-20
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\images\progress-bg.png
  • c:\Documents and Settings\test user\Local Settings\Temp\is1438683437\1572444273.cfg
    Size
    234
    SHA-1
    f21b22a7b78a5930d07263feac36dfba4885d09b
    MD5
    06ad310791db83581823c4d4558a6a5d
    CRC-32
    80702d6d
    File type
    application/octet-stream
    First seen
    2012-02-04
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\locale\EN.locale
    Size
    2.0K
    SHA-1
    d97050e501e09e859f49ac871b9ad645b8273359
    MD5
    299ce8700041e3e688a29747e0d3b804
    CRC-32
    2edb971b
    File type
    ASCII text / 8-bit Unicode Transformation Format
    First seen
    2011-06-27
  • c:\Documents and Settings\test user\Local Settings\Temp\ish119875\css\sdk-ui\progress-bar.css
    Size
    501
    SHA-1
    da659b6a37b18c26a8f7342f93c03fe649ab6344
    MD5
    5ccd1d0dc39bb6ae4cd6b58f0b310eb0
    CRC-32
    1601b666
    File type
    Cascading Style Sheet
    First seen
    2011-02-22
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    Name
    test_item.exe
Registry Keys Modified
  • HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
    ID
    0x2a425e19
HTTP Requests
  • http://cdneu.solvefile.com/Prod/AudioConverter-v2.cis
  • http://cdnus.solvefile.com/Prod/AudioConverter-v2.cis
DNS Requests
  • cdneu.solvefile.com
  • cdnus.solvefile.com
  • os.solvefile.com

download Try Sophos products for free
Download now