downloadsetup.exe

Setup

Itzhak Shternberg

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions using the JustPlug.it browser framework. The application downloadsetup.exe by Itzhak Shternberg has been detected as adware by 24 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
Premium  (signed by Itzhak Shternberg)

Product:
Setup

Description:
Installer

Version:
2012.9.27.1933

MD5:
4feebc19a46ae3b9c5936b8b78c42dc7

SHA-1:
732c7b8ff5dda90444ef2590cc83b529c00ea34b

SHA-256:
c75f0825796944102c62c30e938e4a1256c4fe260a0f49b80f63babdb0d4db77

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
4/25/2024 10:12:35 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.InstallMate
7.1.1

AhnLab V3 Security
PUP/Win32.TSULoader
2014.07.18

Avira AntiVirus
ADWARE/InstallRex.Gen
7.11.141.146

avast!
Win32:InstalleRex-CG [PUP]
141025-0

AVG
MalSign.Skodna
2015.0.3297

Baidu Antivirus
Adware.Win32.InstalleRex
4.0.3.14118

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
Application.Win32.Bundledz.C
18053

Dr.Web
Adware.Downware.448
9.0.1.05190

ESET NOD32
Win32/InstallMate potentially unwanted application
7.0.302.0

IKARUS anti.virus
PUP.InstallRex
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.183.13407

NANO AntiVirus
Riskware.Win32.Downware.cvbqyt
0.28.0.58873

nProtect
Backdoor/W32.Clack.301504
14.09.17.01

Panda Antivirus
PUP/TSUploader
14.11.08.12

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.ItzhakShternberg.N
14.11.8.0

Rising Antivirus
PE:PUF.InstallRex!1.9E4C
23.00.65.141106

Sophos
InstallRex
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-InstallMate
10251

Total Defense
Win32/Tnega.aDQSBaD
37.0.10981

Trend Micro House Call
HV_INSTALLEREX_CI05361D.RDXN
7.2.312

VIPRE Antivirus
Installerex/WebPick
28050

Zillya! Antivirus
Backdoor.Clack.Win32.181
2.0.0.1905

File size:
294.4 KB (301,504 bytes)

Product version:
1.0

Copyright:
Copyright © 2010 Premium

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\downloadsetup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/7/2012 5:00:00 PM

Valid to:
6/8/2013 4:59:59 PM

Subject:
CN=Itzhak Shternberg, O=Itzhak Shternberg, STREET=Belkind 2, L=Tel Aviv, S=Israel, PostalCode=62154, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009DFDC7DD83734FFB61F158A9759A6F69

File PE Metadata
Compilation timestamp:
8/21/2012 7:07:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:406sehnP8zOWy66Z6jef4EVZDDdHv3CtnUviZ1RfxiRMz5A8uh36OjBe:406s2nPeDh6YjI4E3DDxr0RfxMMzi8uI

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Entropy:
7.9595

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file downloadsetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=13195722&publisher_id=319&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=39587166&external_id=0&session_id=79174332&hardware_id=92370054&installer_file_name=downloadsetup

Remove downloadsetup.exe - Powered by Reason Core Security