fl_setup.exe

Fileadventure

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application fl_setup.exe, “Swift Installer ” by Fileadventure has been detected as adware by 29 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from secure.pn-installer45.com.
Publisher:
Swift Installer   (signed by Fileadventure)

Product:
Swift Installer

Description:
Swift Installer

Version:
2.4.8.1

MD5:
95ecd077e3fa4900d47466978bda1593

SHA-1:
da2ee91f132a94f241be5e8dbf1043b19961d1a9

SHA-256:
bda590686e74d32eef54be31f75042fae096d2dbb726264ac9f9616ea4e2ce93

Scanner detections:
29 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:31:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.35
551

AhnLab V3 Security
2014.12.10

Avira AntiVirus
ADWARE/iBryte.Gen7
7.11.185.204

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150803

AVG
Adware AdPlugin
2016.0.3029

Bitdefender
Gen:Variant.Adware.Strictor.71370
1.0.20.1075

Clam AntiVirus
Win.Adware.Strictor-362
0.98/20197

Comodo Security
Application.Win32.Ibryte.NW
20315

Dr.Web
Trojan.DownLoader11.49526
9.0.1.0215

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.35
8.15.08.03.06

ESET NOD32
Win32/Adware.iBryte.BR application
9.7.0.302.0

F-Prot
W32/A-a1a6e5b1
v6.4.7.1.166

F-Secure
Riskware.Gen:Variant.Application.Bundler
11.2015-03-08_2

G Data
Win32.Adware.IBryte
15.8.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.186.14280

Kaspersky
not-a-virus:AdWare.Win32.iBryte
14.0.0.1639

Malwarebytes
PUP.Optional.Fusion.A
v2015.08.03.06

McAfee
IBryte-FSO
5600.6685

MicroWorld eScan
Gen:Variant.Adware.Kazy.491026
16.0.0.645

NANO AntiVirus
Trojan.Win32.Buzus.djslbz
0.28.6.63850

Norman
Gen:Variant.Adware.Strictor.71370
11.20150803

nProtect
Trojan/W32.Buzus.339832
15.02.25.01

Panda Antivirus
Trj/Genetic.gen
15.08.03.06

Reason Heuristics
PUP.Adknowledge.Fileadventure.Installer (M)
15.8.3.6

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4778314
34232

Zillya! Antivirus
Trojan.Buzus.Win32.123141
2.0.0.2081

File size:
331.9 KB (339,832 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) Swift Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\fl_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/13/2014 8:00:00 PM

Valid to:
7/14/2015 7:59:59 PM

Subject:
CN=Fileadventure, O=Fileadventure, STREET=4600 Madison Ave FL 10, L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2EF279A57EB2CCFE0FCD97FC0F239ADE

File PE Metadata
Compilation timestamp:
12/4/2014 1:00:29 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:05dlWaI3qsdtco9QUGIVC9RMWApKwev17Eblkz25Xg74VBrbQ3k5u8I0UjZ299yU:HP3jzNInMWpw1bH674VBrbQmuzZM9jBP

Entry address:
0x185F3

Entry point:
E8, 5A, A7, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 84, A6, 43, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 84, A6, 43, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F...
 
[+]

Entropy:
5.9355

Code size:
184 KB (188,416 bytes)

The file fl_setup.exe has been seen being distributed by the following URL.

Remove fl_setup.exe - Powered by Reason Core Security