express_installer.exe

SETUP DOT EXE

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application express_installer.exe, “Fusion Install ” by SETUP DOT EXE has been detected as adware by 26 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Fusion Install   (signed by SETUP DOT EXE)

Product:
Fusion Install

Description:
Fusion Install

Version:
2.4.8.1

MD5:
ec7d8bb963cbc1016e2e85490cea6044

SHA-1:
86b29dca1375281aea8655b03f429042504f74d1

SHA-256:
02ade6c50b966f91c52692fb61596296efd190167834ef1ad0685a7c0efeed3b

Scanner detections:
26 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 8:40:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.OptimumInstaller.3
834

Avira AntiVirus
Adware/iBryte.bxjb
7.11.180.234

AVG
Adware AdPlugin.FJ
2014.0.4040

Bitdefender
Gen:Variant.Application.Bundler.OptimumInstaller.3
1.0.20.1485

Clam AntiVirus
Win.Adware.Agent-6929
0.98/21411

Comodo Security
Application.Win32.IBryte.S
19887

Dr.Web
Trojan.DownLoader9.59538
9.0.1.05190

ESET NOD32
Win32/AdWare.iBryte.S application
7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.13751
10/24/2014

F-Prot
W32/A-512ed8f8
v6.4.7.1.166

F-Secure
Gen:Variant.Application.Bundler
11.2014-24-10_6

IKARUS anti.virus
t3scan.1.7.8.0

K7 AntiVirus
Unwanted-Program
13.185.13789

Malwarebytes
v2014.10.24.06

MicroWorld eScan
Gen:Variant.Application.Bundler.OptimumInstaller.3
15.0.0.891

NANO AntiVirus
Trojan.Win32.Downware.culecy
0.28.2.62841

Quick Heal
Adware.iBryte.DK4
10.14.14.00

Reason Heuristics
PUP.Installer.SETUPDOTEXE.R
14.10.24.6

Rising Antivirus
PE:Malware.iBryte!6.14B5
23.00.65.141022

SUPERAntiSpyware
10280

Vba32 AntiVirus
Downloader.Agent
3.12.26.3

VIPRE Antivirus
Threat.4150696
33706

Zillya! Antivirus
Downloader.Agent.Win32.185821
2.0.0.1966

File size:
219.3 KB (224,544 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Fusion Install

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\express_installer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/4/2013 10:00:00 AM

Valid to:
9/21/2014 9:59:59 AM

Subject:
CN=SETUP DOT EXE, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SETUP DOT EXE, L=Kansas City, S=Missouri, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
348784BF9B5AF7CB50276EA8463A9048

File PE Metadata
Compilation timestamp:
3/28/2014 4:00:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:RMO2xFZz4ycWJikYO+6DbJn8xupQW8Jm8ZzlS5KbkpEh:QxFZz5ceTZCueWLYLbkpEh

Entry address:
0xDF1B

Entry point:
E8, BC, 47, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, AC, 82, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 5C, 80, 42, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
6.4070

Code size:
155 KB (158,720 bytes)

Remove express_installer.exe - Powered by Reason Core Security