filemenutools-setup.exe

FileMenu Tools

LopeSoft

The application filemenutools-setup.exe has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.lopesoft.com.
Publisher:
LopeSoft

Product:
FileMenu Tools

Version:
FileMenu Tools 6.7

MD5:
31598c2223b870e1ed527bd8764480d1

SHA-1:
d6ad63044a7a3755d3c49f0689b0186d6faa6ac6

SHA-256:
7a73cffb9dcf2904bb77b1e265961d29ce098dde854c9749165fbb20d82c374f

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/23/2024 6:16:08 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AF
9.11090

Reason Heuristics
PUP.InstallMonetizer.Bundle (M)
16.3.10.15

File size:
11.1 MB (11,646,456 bytes)

Product version:
6.7

Copyright:
Copyright © 1998-2015, LopeSoft.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:9W62b7Ld4ZlLiwG73Hy99zYq2KTRtwT0ioohVNnAI7OPNWTRMZB8H9qdfRRUX6lf:9W62b2mS9BzWQioIrA0nGJwCW41N16cH

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file filemenutools-setup.exe has been seen being distributed by the following URL.

Remove filemenutools-setup.exe - Powered by Reason Core Security