bitzippersetup.exe

BitZipper

Bitberry Software

The application bitzippersetup.exe, “Open RAR, ZIP, 7Z, ISO and many other files ” by Bitberry Software has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
Bitberry Software   (signed by Bitberry Software)

Product:
BitZipper

Description:
Open RAR, ZIP, 7Z, ISO and many other files

Version:
2011.07.21

MD5:
ab15d75e7722cb354a379d5e0932ac03

SHA-1:
8c031f95f2df79140a0be564c9efc960134bf16d

SHA-256:
b04bd7667a872c665a7f6fac74b55e68ac610a7a9a3ec9c054b05e4657e509eb

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/26/2024 5:57:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bitberry.BitberrySoftware.Installer (M)
15.8.6.8

Rising Antivirus
Trojan.Win32.Generic.1331D6F6
23.00.65.15911

Vba32 AntiVirus
Signed-Adware.InstallCore
3.12.18.4

File size:
5.3 MB (5,514,400 bytes)

Product version:
2010

Copyright:
Copyright © 1999-2011 Bitberry Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bitzippersetup.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
10/31/2010 7:00:00 PM

Valid to:
10/31/2013 6:59:59 PM

Subject:
CN=Bitberry Software, O=Bitberry Software, STREET=Blomsterhaven 42, L=Holbaek, S=n/a, PostalCode=4300, C=DK

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00BFCE655DC312403F105230416ACDF5B3

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:YajRmN4K7R2H/egdATdHOjnVBjH5ROqznlNmAagmY3afYvqp0xW6lmtPlYEKHn3:XmN4KYWgdsHOjVFOonHmJZq80l8PlYTX

Entry address:
0x9A94

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 32, 96, FF, FF, E8, 39, A8, FF, FF, E8, 64, CA, FF, FF, E8, AB, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, 47, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 10, A1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 94, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, E3, 96, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9991

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

Remove bitzippersetup.exe - Powered by Reason Core Security