gimpsetup.exe

appbundler.com

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The application gimpsetup.exe by appbundler.com has been detected as adware by 28 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
appbundler.com  (signed and verified)

Description:
Setup

Version:
3.0.113.3

MD5:
5ec10817c7c7bd3997cddf55492e00cc

SHA-1:
e50e364171d00009f10e7cfcab6fdb0d1e379fca

SHA-256:
69053a8af790143be2282c1bc3d2ad0e16aaa8c2d19a677117ea8e1d8f57405c

Scanner detections:
28 / 68

Status:
Adware

Analysis date:
4/26/2024 8:17:48 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.ScreenSaver
7.1.1

AhnLab V3 Security
Adware/Win32.ScreenSaver
2013.03.07

Avira AntiVirus
TR/Graftor.Elzob.15338.1
7.11.63.240

avast!
Win32:Zango-AQ [PUP]
2014.9-150213

AVG
Generic5
2016.0.3200

Bitdefender
Gen:Variant.Adware.Graftor.30458
1.0.20.220

Comodo Security
ApplicUnwnt.Win32.AdWare.ScreenSaver.DI
15480

Dr.Web
Adware.Hotbar.700
9.0.1.044

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.30458
8.15.02.13.04

ESET NOD32
Win32/Adware.HotBar (variant)
9.8087

Fortinet FortiGate
Adware/Hotbar
2/13/2015

F-Prot
W32/HotBar.O.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Adware.Graftor.30458
11.2015-13-02_6

G Data
Gen:Variant.Adware.Graftor.30458
15.2.22

IKARUS anti.virus
not-a-virus:AdWare.Win32
t3scan.2.0.0.0

K7 AntiVirus
Adware
13.163.8312

Kaspersky
not-a-virus:AdWare.Win32.ScreenSaver
14.0.0.2494

Malwarebytes
Adware.AdBundle
v2015.02.13.04

McAfee
Adware-HotBar.d
5600.6856

MicroWorld eScan
Gen:Variant.Adware.Graftor.30458
16.0.0.132

NANO AntiVirus
Trojan.Win32.Graftor.bbkjam
0.22.8.50837

Norman
180Solutions.BSE
11.20150213

Quick Heal
Adware.Hotbar.B5
2.15.12.00

Reason Heuristics
PUP.Installer.Pinball
15.2.13.4

Rising Antivirus
Adware.Hotbar!481A
23.00.65.15211

Total Defense
Win32/Zango.Pinball.B[HOTBAR]
37.0.10323

Vba32 AntiVirus
AdWare.Win32.ScreenSaver.e
3.12.20.2

VIPRE Antivirus
Pinball Corporation.
15894

File size:
340.7 KB (348,848 bytes)

Product version:
3.0.113.3

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\gimpsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/10/2012 12:00:00 AM

Valid to:
1/9/2015 11:59:59 PM

Subject:
CN=appbundler.com, OU=Ops, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=appbundler.com, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
12E277DA6E659BFE14CD01F5A2AA95C5

File PE Metadata
Compilation timestamp:
2/22/2013 5:21:16 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:1fZ/nwzIhoZib9i0ju9BKVoEZUWdPBYMP1XbfKB3M9agVYVyqO7N:1fpPOZiBiq3zxrYSXGB3MEgVYVyqOJ

Entry address:
0xBCF50

Entry point:
60, BE, 00, B0, 46, 00, 8D, BE, 00, 60, F9, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.8842

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
332 KB (339,968 bytes)

Remove gimpsetup.exe - Powered by Reason Core Security