Home Malware Programs Potentially Unwanted Programs (PUPs) InstallCore

InstallCore

Posted: August 30, 2013

Threat Metric

Ranking: 26
Threat Level: 1/10
Infected PCs: 10,398,800
First Seen: August 30, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

InstallCore is a Potentially Unwanted Program, which encompasses adware applications, installs toolbars or has other uncertain intentions. Technically, InstallCore is not a virus, but it carries a variety of issues such as interfering with the Internet user's experience. InstallCore can access the affected PC packaged with freeware and shareware applications (video recording/streaming, download-managers or PDF creators). InstallCore is also packaged within the custom installer on many download websites so if the PC user has downloaded a particular tool from these websites, he might also installed InstallCore throughout the setup process of the particular tool.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0002d9 File name: f_0002d9
Size: 4.05 MB (4054648 bytes)
MD5: 3503a9bd742e8c006318a45e0e74124e
Detection count: 1,623
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Google\Chrome\User Data\Default\Cache\f_0002d9
Group: Malware file
Last Updated: October 12, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\bitcomet_setup (1).exe File name: bitcomet_setup (1).exe
Size: 4.05 MB (4056856 bytes)
MD5: 3198d49b3340abc014fe48105dbcb1e0
Detection count: 927
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\bitcomet_setup (1).exe
Group: Malware file
Last Updated: February 21, 2025
%SYSTEMDRIVE%\Users\<username>\Desktop\5597810067537920\6c480bb3548f03a2b70953942943c9c7efd205d7e45d694783fa4ad0ea6f8bf2 File name: 6c480bb3548f03a2b70953942943c9c7efd205d7e45d694783fa4ad0ea6f8bf2
Size: 4.05 MB (4053136 bytes)
MD5: 4ac6d206aa429c9eb7ea9f31e6653e65
Detection count: 464
Path: %SYSTEMDRIVE%\Users\<username>\Desktop\5597810067537920\6c480bb3548f03a2b70953942943c9c7efd205d7e45d694783fa4ad0ea6f8bf2
Group: Malware file
Last Updated: October 12, 2024
C:\Users\<username>\AppData\Local\Temp\Bit5AA8.tmp.exe File name: Bit5AA8.tmp.exe
Size: 4.04 MB (4048096 bytes)
MD5: f83f96418b9cc63755101118a0ae59d5
Detection count: 391
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\Bit5AA8.tmp.exe
Group: Malware file
Last Updated: April 8, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit3763.tmp.exe File name: Bit3763.tmp.exe
Size: 4.04 MB (4048480 bytes)
MD5: a482b3b670befeb3a73af1dfafea9602
Detection count: 389
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit3763.tmp.exe
Group: Malware file
Last Updated: October 12, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Microsoft\Windows\INetCache\IE\L4L3DJHF\bitcomet_setup[1].exe File name: bitcomet_setup[1].exe
Size: 4.05 MB (4055896 bytes)
MD5: ee250a5366e37d0054e574179bbac75b
Detection count: 386
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Microsoft\Windows\INetCache\IE\L4L3DJHF\bitcomet_setup[1].exe
Group: Malware file
Last Updated: October 12, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_0078fc File name: f_0078fc
Size: 3.92 MB (3928694 bytes)
MD5: 0a8ef10c91fc9dd32fb62b5b6a3cc6ad
Detection count: 337
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Microsoft\Edge\User Data\Default\Cache\f_0078fc
Group: Malware file
Last Updated: October 14, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit3D60.tmp.exe File name: Bit3D60.tmp.exe
Size: 4.05 MB (4056088 bytes)
MD5: b0c67496ee35317cc2a4bd4a41c648b1
Detection count: 316
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit3D60.tmp.exe
Group: Malware file
Last Updated: January 27, 2025
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\BitB646.tmp.exe File name: BitB646.tmp.exe
Size: 4.04 MB (4048592 bytes)
MD5: f603b2aa3e80ff9a1fb44c0955cd04e0
Detection count: 262
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\BitB646.tmp.exe
Group: Malware file
Last Updated: April 8, 2024
%SYSTEMDRIVE%\Users\<username>\Downloads\aTube_Catcher_2241024900.exe File name: aTube_Catcher_2241024900.exe
Size: 3.96 MB (3962472 bytes)
MD5: 4e4c2e5a5dc4c8a47d8f69292f91a89a
Detection count: 260
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Downloads\aTube_Catcher_2241024900.exe
Group: Malware file
Last Updated: August 12, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit8508.tmp.exe File name: Bit8508.tmp.exe
Size: 4.05 MB (4053424 bytes)
MD5: 2fc58c411b7f32a701b52294134ad060
Detection count: 253
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit8508.tmp.exe
Group: Malware file
Last Updated: October 12, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit79D0.tmp.exe File name: Bit79D0.tmp.exe
Size: 4.06 MB (4060832 bytes)
MD5: 7e6328af4e4da7f5c42c8d98494597af
Detection count: 230
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit79D0.tmp.exe
Group: Malware file
Last Updated: September 14, 2023
c:\Users\<username>\downloads\filezilla_3.49.0_win64_sponsored-setup.exe File name: filezilla_3.49.0_win64_sponsored-setup.exe
Size: 10.86 MB (10862880 bytes)
MD5: 8dbbaa884b8f0b1571dbc32acf13b133
Detection count: 199
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\downloads
Group: Malware file
Last Updated: January 19, 2024
C:\Users\<username>\AppData\Local\Temp\BitA2C9.tmp.exe File name: BitA2C9.tmp.exe
Size: 4.05 MB (4053864 bytes)
MD5: 38435866bda2da5d879a9c8626713a26
Detection count: 190
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\BitA2C9.tmp.exe
Group: Malware file
Last Updated: November 17, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit232A.tmp.exe File name: Bit232A.tmp.exe
Size: 4.05 MB (4055424 bytes)
MD5: e0523261bf58a39304adc6011700bef9
Detection count: 183
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit232A.tmp.exe
Group: Malware file
Last Updated: August 15, 2024
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit5E0.tmp.exe File name: Bit5E0.tmp.exe
Size: 4.05 MB (4052288 bytes)
MD5: ab7859996516e94088925cd6da773a06
Detection count: 148
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Bit5E0.tmp.exe
Group: Malware file
Last Updated: October 12, 2024
%SYSTEMDRIVE%\Users\<username>\Downloads\aTube_Catcher_1332679800.exe File name: aTube_Catcher_1332679800.exe
Size: 3.96 MB (3966312 bytes)
MD5: 42ff6047caa0ff7dea7b1604865ba3a2
Detection count: 115
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Downloads\aTube_Catcher_1332679800.exe
Group: Malware file
Last Updated: May 10, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Baixaki_Format Factory_2913681990.exe File name: Baixaki_Format Factory_2913681990.exe
Size: 3.13 MB (3137024 bytes)
MD5: 2125d5a9106f210f322e2032b837c990
Detection count: 101
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\Baixaki_Format Factory_2913681990.exe
Group: Malware file
Last Updated: July 9, 2023
C:\$Recycle.Bin\S-1-5-21-3816129693-3434447997-1862857808-1000\$R61WGVT.exe File name: $R61WGVT.exe
Size: 3.96 MB (3961968 bytes)
MD5: bf02d49760cfa812c5b9c13739069917
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: C:\$Recycle.Bin\S-1-5-21-3816129693-3434447997-1862857808-1000\$R61WGVT.exe
Group: Malware file
Last Updated: April 5, 2024
C:\Users\<username>\Downloads\aTube_Catcher_0070660122.exe File name: aTube_Catcher_0070660122.exe
Size: 3.96 MB (3965016 bytes)
MD5: 8b06462f7bcb9264e3c44fb6cfc7c6c8
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\aTube_Catcher_0070660122.exe
Group: Malware file
Last Updated: May 26, 2022
c:\Users\<username>\appdata\local\temp\messengerfordesktopsetup_1818897196.exe File name: messengerfordesktopsetup_1818897196.exe
Size: 2.37 MB (2377588 bytes)
MD5: 5dc9126345c686139c87645f81481299
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\appdata\local\temp
Group: Malware file
Last Updated: August 28, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%localappdata%\[RANDOM CHARACTERS].delHKEY..\..\..\..{RegistryKeys}Software\1Q1F1S1C1P1E1C1F1N1C1T1H2UtF1E1ISoftware\csastatsSoftware\InstallCoreSoftware\ProductSetupSoftware\SoftSuma\Evasi0n_Setup.exeSOFTWARE\Wow6432Node\InstallCore
Loading...