debloater-setup-v3.90.exe

Debloater

Gatesjunior Developer

The executable debloater-setup-v3.90.exe, “Setup Launcher Unicode” has been detected as malware by 11 anti-virus scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from rootjunkysdl.com.
Publisher:
Gatesjunior Developer

Product:
Debloater

Description:
Setup Launcher Unicode

Version:
3.90

MD5:
3400a196e280bf8da36690079f06348c

SHA-1:
67126f328eeb5fb59e66933950c0479616556447

SHA-256:
72b20dcc1ed420714ae99a57ec76ff6dc2a7b9a04bccca1e85c2bd0bf702e6e9

Scanner detections:
11 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 2:59:23 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160326-0

AVG
Win32/Sality
2015.0.4355

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.217.1197.0

Norman
Win32.Sality.3
02.04.2016 17:35:19

VIPRE Antivirus
Threat.4758034
48238

File size:
2.9 MB (3,064,177 bytes)

Product version:
3.90

Copyright:
Copyright (c) 2013 Flexera Software LLC. All Rights Reserved.

Original file name:
InstallShield Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\debloater-setup-v3.90.exe

File PE Metadata
Compilation timestamp:
10/30/2013 1:48:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:dfyNKOKBaVOu07ieyFRT2JNZff/rxyUwaMa6H3dxCy0V/oHq3yJeDvgRviB:dfTBaVOu07ie3ZfXNZPMPdL0VKq3yJ36

Entry address:
0x6B0FB

Entry point:
87, CB, 49, 72, 04, 1C, DF, 0F, CF, BE, 5C, B2, 00, 00, 0F, AF, FF, 81, EA, E7, 20, 23, 80, 33, DE, 81, FF, 63, 58, 00, 00, 75, 05, 8B, FF, 12, E1, 46, 3B, CE, 70, 02, F6, D9, EB, 02, 34, 6B, 8A, D6, 18, E2, E8, 00, 00, 00, 00, 58, 8B, C9, 86, F1, 2B, DF, 8D, 2D, 6C, 18, B0, 0F, 47, F7, C0, A8, 03, 80, 32, 68, 3D, 05, 00, 00, B3, 66, 5A, 86, FF, 81, F2, 3D, 05, 00, 00, F6, DF, 8D, 1D, 7F, 89, 25, 14, 81, C2, 51, 0F, 00, 00, 76, 03, 0F, AF, CA, 81, EA, 50, 0F, 00, 00, EB, 08, BD, 06, 31, E9, 75, 0F, B7, EA...
 
[+]

Entropy:
7.6935

Code size:
699 KB (715,776 bytes)

The file debloater-setup-v3.90.exe has been seen being distributed by the following URL.

Remove debloater-setup-v3.90.exe - Powered by Reason Core Security