Hello true indian and alan1998,
Good you two reported here.
It is the installer that is involved and that installer (wrapper) should be detected as junkware laden.
See the Sophos analysis here:
http://www.sophos.com/en-us/threat-center/threat-analyses/adware-and-puas/InstallRex/detailed-analysis.aspxThis is something we see happening more and more and it is really frustrating for those users,
that download a legit program and are troubled by nasty and very hard to uninstall crap- and junkware.
CNet downloads also come with this uninvited junk installer for their downloads.
Just google this combination: installmate adware and you get many interesting info, my good friends,
dware InstallMate
SHA256: ecf7e1de8ef7a049a1abb3fb36e8b47786b7d96aa5123a4e86e2a3a44bbe11b0
SHA1: b87fe0346097f3b49b7fb01b85ef0004162bfc5a
MD5: 5192e5dcdbfc466042f55386a03f89a3
File size: 305456 bytes
Created files:
%WinDir%\TEMP\Tsu6193197D.dll – Adware InstallMate
%WinDir%\TEMP\{5CF5495C-FB77-790F-9BE4-B35587166BAA}\Setup.exe – Adware InstallMate
%WinDir%\TEMP\{5CF5495C-FB77-790F-9BE4-B35587166BAA}\_Setup.dll – Adware InstallMate
%WinDir%\TEMP\{5CF5495C-FB77-790F-9BE4-B35587166BAA}\_Setupx.dll – Adware InstallMate
polonus