irsetup.exe

Setup Factory Runtime

Mindspark Interactive Network

This is the installer stub for the Mindspark (Indigo Rose Corporation/Ask) browser toolbar which provides the offer to the end user to install the toolbar and set the browser's search, home page and new tab to an Ask.com search destination. The application irsetup.exe, “Setup Application” by Mindspark Interactive Network has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Mindspark Custom Setup installer. It is also typically executed from the user's temporary directory.
Publisher:
Indigo Rose Corporation  (signed by Mindspark Interactive Network)

Product:
Setup Factory Runtime

Description:
Setup Application

Version:
9.1.0.0

MD5:
add1543965eb2f2c7dfe1e8c625323cd

SHA-1:
baec5888b43a104a6a67437e9ce1eaa0cf4bec02

SHA-256:
b1ca265fa5a1f5222db21c7ea7edab938259e6af4fdcd1d8baef136545c39f5f

Scanner detections:
3 / 68

Status:
Potentially unwanted

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/16/2024 5:18:22 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Mindspark-A [PUP]
2014.9-141126

AVG
Zango
2015.0.3279

Reason Heuristics
PUP.Installer.MindsparkInteractiveNetwork.H
14.11.26.10

File size:
1.3 MB (1,351,008 bytes)

Product version:
9.1.0.0

Copyright:
Runtime Engine Copyright © 2012 Indigo Rose Corporation (www.indigorose.com)

Trademarks:
Setup Factory is a trademark of Indigo Rose Corporation

Original file name:
suf_rt.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Mindspark Custom Setup

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\irsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/9/2012 8:00:00 PM

Valid to:
5/6/2015 7:59:59 PM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
6/14/2012 11:50:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:zFYGY9+9d/G7P9lkQ/exnzGn4dLsUvqkaT+0BpCCh+PDeda:yN26FOnzGn6LJvqkwnpC+md

Entry address:
0x3C2D10

Entry point:
60, BE, 00, 30, 68, 00, 8D, BE, 00, E0, D7, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Entropy:
7.9209

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
1.3 MB (1,310,720 bytes)

Remove irsetup.exe - Powered by Reason Core Security