google-chrome-setup.exe

SETUP DOT EXE

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application google-chrome-setup.exe, “Premium Installer ” by SETUP DOT EXE has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Premium Installer   (signed by SETUP DOT EXE)

Product:
Premium Installer

Description:
Premium Installer

Version:
1.3.7.2

MD5:
8ec1eb256a5301a9ac4849dcbe7008c2

SHA-1:
3e38145c67b56610e58e733bded6deec26d1744d

SHA-256:
3cb30255554dadbccc8b31d50a2d3ddaa19f0fc2480484953e2144c55ff4527d

Scanner detections:
19 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/1/2024 10:06:14 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Downloader
7.1.1

Avira AntiVirus
Adware/iBryte.bxka
7.11.149.220

avast!
Win32:PUP-gen [PUP]
2014.9-140515

AVG
Adware AdPlugin.DV
2014.0.3950

Comodo Security
Application.Win32.IBryte.WX
18279

Dr.Web
Trojan.DownLoader9ENT.53807
9.0.1.0135

ESET NOD32
Win32/AdWare.iBryte (variant)
8.9805

F-Prot
W32/DomaIQ.G.gen
v6.4.7.1.166

IKARUS anti.virus
not-a-virus:Downloader.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.177.12095

Kaspersky
HEUR:Trojan.Win32.Generic
14.0.0.3861

Malwarebytes
v2014.05.15.05

NANO AntiVirus
Trojan.Win32.DownLoader9ENT.cwlbzr
0.28.0.59911

Reason Heuristics
PUP.Installer.SETUPDOTEXE.T
14.5.15.15

Rising Antivirus
PE:Malware.Agent!6.1684
23.00.65.14513

Vba32 AntiVirus
Downloader.Agent
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29246

Zillya! Antivirus
Downloader.Agent.Win32.186354
2.0.0.1789

File size:
232.8 KB (238,368 bytes)

Product version:
1.3.7.2

Copyright:
Copyright (C) 2013 Premium Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\google-chrome-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/3/2013 8:00:00 PM

Valid to:
9/20/2014 7:59:59 PM

Subject:
CN=SETUP DOT EXE, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SETUP DOT EXE, L=Kansas City, S=Missouri, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
348784BF9B5AF7CB50276EA8463A9048

File PE Metadata
Compilation timestamp:
4/11/2014 5:00:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:eiA3aScsa2xIo/Zmlk89Q4hP+k8JiSM1g3YktIWLKV5LIpR+0:elaScsdxIoaq4F+9o2LKjIpR+0

Entry address:
0xD7EC

Entry point:
E8, 0B, 48, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, AC, B2, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 60, B0, 42, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
6.3805

Code size:
167 KB (171,008 bytes)

Remove google-chrome-setup.exe - Powered by Reason Core Security