anyprotectsetup.exe

Online Backup!

ClickMeIn Limited

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application anyprotectsetup.exe has been detected as adware by 2 anti-malware scanners. The program is a setup application that uses the installCore installer, however the file is not signed with an authenticode signature from a trusted source. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from download-servers.com. While running, it connects to the Internet address 198.105.215.132.static.midphase.com on port 80 using the HTTP protocol.
Publisher:
ClickMeIn Limited

Product:
Online Backup!

Description:
Setup

Version:
1.0.0.1

MD5:
f0ff59ee51c34da4dd5449eddc53b0b5

SHA-1:
05a026bbd31caf932e282197ed6eec6d18a30232

SHA-256:
34c947ab9d589e7fa247cbd037cc8445c69cc28a97ed870afa046df0d610f0c2

Scanner detections:
2 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/19/2024 6:15:09 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.ClickMeInLimited.P
14.9.17.20

Sophos
ClickMeIn Installer
4.98

File size:
597.7 KB (612,006 bytes)

Product version:
1.0.0.1

Copyright:
Copyright 2013

Trademarks:
Registered trademark of CMI

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\anyprotectsetup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:6E3znmRxVY/l46YH1N3WrBo8nLMyXkdoFyjgTuomgZc348wrf:6EDmRxCdAT3W1oDAIjgTuomgZcI8wL

Entry address:
0x323F

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 27, 7A, 00, E8, 09, 2C, 00, 00, A3, E4, 26, 7A, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, DC, 79, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, E0, 1E, 7A, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 80, 7A, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9668

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file anyprotectsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to 198.105.215.132.static.midphase.com  (198.105.215.132:80)

Remove anyprotectsetup.exe - Powered by Reason Core Security