gu4setup.exe

Glarysoft Ltd

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.filepuma.com and multiple other hosts.
Publisher:
Glarysoft Ltd  (signed and verified)

MD5:
1d77d8fc64e96be5d3600cd192eab0fd

SHA-1:
121d21a26ddaab4eed9a3e46d6e60a5670d54455

SHA-256:
b5352988b30ed8475b341cdadfa9631c2d80461ba9a4b6d335da7f1f74f71a43

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 8:35:26 PM UTC  (today)

File size:
11.4 MB (11,946,800 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\gu4setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/1/2012 8:00:00 AM

Valid to:
12/2/2015 7:59:59 AM

Subject:
CN=Glarysoft Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Glarysoft Ltd, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ABBA622E23F817B27D68D43E6E39093

File PE Metadata
Compilation timestamp:
12/6/2009 6:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:ScIQVXS6eINibHU6i8n0pXi8WTCgdn7ShE6YIR6HcS:5IsCtIIb061nWJWGgHyY

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9992

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file gu4setup.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file gu4setup.exe has been seen being distributed by the following 50 URLs.

http://www.filepuma.com/file/1388687787c4901/glary_utilities_4.3.0.80/0/.../

http://www.filepuma.com/file/1388178491c4901/glary_utilities_4.3.0.80/0/.../

Latest 30 of 95 download URLs

Scan gu4setup.exe - Powered by Reason Core Security