fileviewerlite12-setup.exe

Sanflex

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application fileviewerlite12-setup.exe by Sanflex has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from windowsfileviewer.com.
Publisher:
Sanflex  (signed and verified)

MD5:
ffc98f8e6d3b82c42c1becbf371aad65

SHA-1:
b65f49261a7c882066c667ec7b0207aeb245d37f

SHA-256:
e22c0b69c528ba8017e5dae830bb235acf1dbf182c85781738fef8881b4d2025

Scanner detections:
21 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/1/2024 2:13:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.KJ
6465596

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Downware
2015.02.08

Avira AntiVirus
ADWARE/Adware.Gen
7.11.208.112

AVG
Generic
2016.0.3206

Bitdefender
Application.Bundler.KJ
1.0.20.190

Clam AntiVirus
Win.Adware.Downloadadmin
0.98/20039

Comodo Security
Application.Win32.DownloadAdmin.ANGL
20995

Dr.Web
Adware.Downware.2220
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.KJ
9.0.0.4799

ESET NOD32
Win32/DownloadAdmin.H potentially unwanted application
7.0.302.0

F-Prot
W32/S-4234b123
v6.4.7.1.166

F-Secure
Adware:W32/WebInstallBundle
5.13.68

G Data
Application.Bundler.KJ
15.2.25

K7 AntiVirus
Unwanted-Program
13.193.14895

Malwarebytes
PUP.Optional.DownloadAdmin
v2015.02.07.08

MicroWorld eScan
Application.Bundler.KJ
16.0.0.114

NANO AntiVirus
Riskware.Win32.Downware.djahkt
0.30.0.65070

Reason Heuristics
PUP.Tightrope.Bundler
15.5.3.0

Vba32 AntiVirus
Downloader.Agent
3.12.26.3

VIPRE Antivirus
Threat.4150696
36694

File size:
822.5 KB (842,240 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2014 3:00:00 AM

Valid to:
7/22/2017 2:59:59 AM

Subject:
CN=Sanflex, O=Sanflex, L=SAN FRANCISCO, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
42D7699269B5BB95341F5DA022F6E57D

File PE Metadata
Compilation timestamp:
7/15/2014 7:29:31 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:4xpJfslZtuaVd9lpmhwQbift489IVGD4xJFl6Xqb5Kbmkg8S5:cp9sVuaVdvgVbmgGDijyikg55

Entry address:
0x3345

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2E, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1F, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0D, 24, 00, 00...
 
[+]

Entropy:
7.4901

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file fileviewerlite12-setup.exe has been seen being distributed by the following URL.

Remove fileviewerlite12-setup.exe - Powered by Reason Core Security