GridinSoft Threat Intelligence

FreeFileViewer2011Setup.exe threat report

Detected as Adware.InstallIQ File reputation report
MD5 991f499d2e50655e104efe35d3506510
Latest seen 2023-02-02 23:18:56 (3 years ago)
First seen 2023-02-02 23:18:56 (3 years ago)
Size 2 MB
Publisher W3i, LLC
Signed by W3i, LLC

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Adware.InstallIQ. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Adware.InstallIQ
Recommended action
Scan and remove
Last analysis
2023-02-02 23:18:56 (3 years ago)
File hash
991f499d2e50655e104efe35d3506510
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Adware.InstallIQ.

Timeline

First seen 2023-02-02 23:18:56 (3 years ago); latest analysis 2023-02-02 23:18:56 (3 years ago).

Publisher context

Company metadata: W3i, LLC. Product metadata: InstallIQ Installation Utility.

Digital signature

Signed by W3i, LLC. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

FreeFileViewer2011Setup.exe is a Windows file recorded in the ThreatInfo database. It is associated with InstallIQ Installation Utility. The reported company name is W3i, LLC. The current detection status is Adware.InstallIQ, based on the latest analysis from 2023-02-02 23:18:56 (3 years ago).

If FreeFileViewer2011Setup.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Adware.InstallIQ.

Product Name: InstallIQ Installation Utility
Company Name: W3i, LLC
MD5: 991f499d2e50655e104efe35d3506510
Size: 2 MB
First Published: 2023-02-02 23:18:56 (3 years ago)
Latest Published: 2023-02-02 23:18:56 (3 years ago)
Status: Adware.InstallIQ (on last analysis)
Analysis Date: 2023-02-02 23:18:56 (3 years ago)
FreeFileViewer2011Setup.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

Signed By: W3i, LLC
Status: Valid

The signature on FreeFileViewer2011Setup.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%sysdrive%\progs\viewers

ThreatInfo has observed FreeFileViewer2011Setup.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

Windows 10 100.0%

The most common operating system signal for FreeFileViewer2011Setup.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

FreeFileViewer2011Setup.exe is identified as pe for 32-bit systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Format pe
Architecture 32-bit
Subsystem Windows GUI
Entry point 0x000695d2
Image base 0x00400000

PE Sections:

Sections 29
Raw data 2318336

Section layout highlights raw-size concentration, repeated names, packer markers, and hashes that can be compared across related samples.

.text 545792 bytes · 23.5% of section data
MD5 bf6a295706a01334f21956450910a7e1
.text-co 99328 bytes · 4.3% of section data
Uncommon name
MD5 dc2eb878cd9ed6e8a2e12a0db391d844
.text-co 32256 bytes · 1.4% of section data
Uncommon name
MD5 42219aee9cf92a6b383da455ea0e487c
.text-co 30208 bytes · 1.3% of section data
Uncommon name
MD5 f8cc8f3302b3774d3a323e292725671e
.text-co 13312 bytes · 0.6% of section data
Uncommon name
MD5 6d89eff0132290df007bcb4c63e691bf
.text-co 59392 bytes · 2.6% of section data
Uncommon name
MD5 7e7e610edde4e264ee1117bfa849d68a
.text-co 169984 bytes · 7.3% of section data
Uncommon name
MD5 f3f333374f39707e29b4a25eea80ad7e
.text-co 97792 bytes · 4.2% of section data
Uncommon name
MD5 fed3c682e43ba6e8a490361f3e7bf55d
.text-co 50688 bytes · 2.2% of section data
Uncommon name
MD5 dbadc0d9a180bcd79beb58e6f63d6dbf
.text-co 20992 bytes · 0.9% of section data
Uncommon name
MD5 2f9cbbb01fdd87e2304f556e47319790
.text-co 65536 bytes · 2.8% of section data
Uncommon name
MD5 a885be28bbf5b1a7c8d5dcf86a69758d
.text-co 26112 bytes · 1.1% of section data
Uncommon name
MD5 f4d890dff37154ca8bc3296883ca9a43
.text-ti 28672 bytes · 1.2% of section data
Uncommon name
MD5 975e5648b3cbd7d64dcad8f9df7736f7
.text-co 17408 bytes · 0.8% of section data
Uncommon name
MD5 ac0b35473fe535c2abefb37ca0a54057
.text-fr 88064 bytes · 3.8% of section data
Uncommon name
MD5 a6f46a26ae012d2b9dd046c8c9965dd6
.text-fr 87552 bytes · 3.8% of section data
Uncommon name
MD5 aa9ed44fd4c66b748db69c8c7327a0b0
.text-co 512 bytes · 0.0% of section data
Uncommon name
MD5 f598cbf8457835969610259b15cbb5fd
.rdata 433152 bytes · 18.7% of section data
MD5 e2df26aa85cb9d44f9599338648dc7f6
.data 26624 bytes · 1.1% of section data
MD5 8b719693272c0c9b89ef883a7c082c7b
.data-fr 512 bytes · 0.0% of section data
Uncommon name
MD5 edcc4c1f60419da469450f6320104aa8
.data-co 512 bytes · 0.0% of section data
Uncommon name
MD5 0fbc4318a04a5cea86ebaf81f710dd9a
.data-co 512 bytes · 0.0% of section data
Uncommon name
MD5 b8adfa647a9d2c257e23b7b9250b8ba9
.data-co 512 bytes · 0.0% of section data
Uncommon name
MD5 b284c8ffab7482a8e225d7368861409c
.data-fr 512 bytes · 0.0% of section data
Uncommon name
MD5 e9c927d63435e8524220ee7802e34a8e
.data-co 512 bytes · 0.0% of section data
Uncommon name
MD5 e9c927d63435e8524220ee7802e34a8e
.data-ti 1024 bytes · 0.0% of section data
Uncommon name
MD5 f8bc1125e63381e5044cad41e80fe735
.data-co 512 bytes · 0.0% of section data
Uncommon name
MD5 8f8260ad5c4393523d88c8df20d5cae8
.data-co 512 bytes · 0.0% of section data
Uncommon name
MD5 382073f6012fcc3801d8b73779a0b249
.rsrc 419840 bytes · 18.1% of section data
MD5 82f2616312f5eeba2029ceb7b4589c51

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

Report conclusion

GridinSoft detects this file as Adware.InstallIQ

This report identifies FreeFileViewer2011Setup.exe by MD5 991f499d2e50655e104efe35d3506510. If the same file is present on your device, scan the system and remove the detected object after confirming the hash and location.

Download GridinSoft Anti-Malware Scan the device and confirm whether this exact hash is present. Check this hash on VirusTotal

Recommended next steps

  • Compare the local file MD5 with 991f499d2e50655e104efe35d3506510.
  • Check the file path, publisher, and signature against the details in this report.
  • Run a GridinSoft scan and remove the object if the same hash is found.