mystartbuttonsetupru.exe

Product Installer

iTVA LLC

The application mystartbuttonsetupru.exe, “Installer for InstallTraffic.com” by iTVA has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
iTVA LLC  (signed and verified)

Product:
Product Installer

Description:
Installer for InstallTraffic.com

Version:
1.0.20.0

MD5:
ae6200f9ea8a9693a0a702b9f6bee37c

SHA-1:
1412f50785830f4066e55e54caac9b50c0632d2e

SHA-256:
ff924addf2c9c0146b02152526c7813e5f3795bf5911c3e3d63fbf7ee52c1960

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 8:14:33 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
iTVA
2016.0.3219

Dr.Web
Adware.Downware.6456
9.0.1.025

ESET NOD32
Win32/Itva
9.11014

IKARUS anti.virus
PUA.Itva
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.191.14645

McAfee
Artemis!AE6200F9EA8A
5600.6875

NANO AntiVirus
Riskware.Win32.Downware.dgvnpv
0.30.0.64448

Reason Heuristics
PUP.Installer.iTVA
15.1.25.3

Sophos
Generic PUA BE
4.98

VIPRE Antivirus
Trojan.Win32.Generic
36656

File size:
2.1 MB (2,223,264 bytes)

Product version:
1.0.20.0

Copyright:
Copyright © 2004-2014 iTVA LLC.

Trademarks:
iTVA,InstallTraffic.

Original file name:
Installer.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\mystartbuttonsetupru.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/23/2012 3:00:00 AM

Valid to:
11/24/2014 2:59:59 AM

Subject:
CN=iTVA LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=iTVA LLC, L=St.Petersburg, S=Russian Federation, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
65EB772671D39CAF088B0D4A828C5E61

File PE Metadata
Compilation timestamp:
7/14/2014 4:39:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:ksYOEYCy3aUZgtiN415X8EcI/af2PquwvrDgUJ37BSxAV3J:COEeap1wIBPquwvrbWAv

Entry address:
0x61EB0

Entry point:
60, BE, 00, 80, 44, 00, 8D, BE, 00, 90, FB, FF, 57, 89, E5, 8D, 9C, 24, 80, C1, FF, FF, 31, C0, 50, 39, DC, 75, FB, 46, 46, 53, 68, 8C, F5, 05, 00, 57, 83, C3, 04, 53, 68, A8, 9E, 01, 00, 56, 83, C3, 04, 53, 50, C7, 03, 03, 00, 00, 00, 90, 90, 90, 90, 90, 55, 57, 56, 53, 83, EC, 7C, 8B, 94, 24, 90, 00, 00, 00, C7, 44, 24, 74, 00, 00, 00, 00, C6, 44, 24, 73, 00, 8B, AC, 24, 9C, 00, 00, 00, 8D, 42, 04, 89, 44, 24, 78, B8, 01, 00, 00, 00, 0F, B6, 4A, 02, 89, C3, D3, E3, 89, D9, 49, 89, 4C, 24, 6C, 0F, B6, 4A...
 
[+]

Code size:
108 KB (110,592 bytes)

Remove mystartbuttonsetupru.exe - Powered by Reason Core Security