Home / malwarePDF  

SoftwareBundler:Win32/Techrelinst


First posted on 05 November 2016.
Source: Microsoft

Aliases :

There are no other names known for SoftwareBundler:Win32/Techrelinst.

Explanation :

Installation

This threat may use any of the following filenames:

  • PDManager.exe
  • PDMSetupDotNet.exe
  • osetup.exe
  • Setup_ODM.exe
  • SetupNew.exe
  • SetupNow.exe
  • SoftwareUpdater.exe


We have seen this software bundle using the following names:
  • Open Download Manager
  • Premier Download Manager
  • Your Updater


The following are some screenshots of this threat using the said names:

Payload

This software bundler installs the browser modifier "Social2Search", which is detected as BrowserModifier:Win32/Soctuseer.

It may also install or bundle the following software:
  • BrowserSafer
  • FindingDiscount
  • KNCTR
  • NotToTrack
  • One System Care
  • PC Accelerate Pro
  • PCBackup360
  • PCKeeper 007
  • Pop Bubbles
  • WebDiscover






Analysis by James Patrick Dee

Last update 05 November 2016

 

TOP