rartozip_setup.exe

Rspark LLC

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application rartozip_setup.exe by Rspark has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from the user's temporary directory.
Publisher:
Rspark LLC  (signed and verified)

MD5:
c4f79c69396eda9de1d338d58fc1347f

SHA-1:
3e15ecc91225e8391949f65848275697f6a1851d

SHA-256:
91cbd6430776e3e4e5dcf5c00401ca30fe9b7e2458705b4c4b586175e0a67499

Scanner detections:
6 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
5/1/2024 10:32:35 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.2081
9.0.1.0127

Malwarebytes
Trojan.Agent
v2014.05.07.01

NANO AntiVirus
Trojan.Win32.Generic.cthmwf
0.28.0.59608

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.Rspark.O
14.5.7.13

Trend Micro House Call
TROJ_GE.7E3A9603
7.2.127

File size:
969.4 KB (992,640 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\rartozip_setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
11/25/2013 12:00:00 AM

Valid to:
1/26/2015 12:00:00 PM

Subject:
CN=Rspark LLC, O=Rspark LLC, L=Seattle, S=Washington, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0ADE80060D1D9FFF62ADB2CF331C657C

File PE Metadata
Compilation timestamp:
12/5/2009 10:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:dcVOeLZk2jfebhDFWkBmFl7uom3qPdIZFGRxXRy8n:cOe9GbXgxyaRxRy2

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9257

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove rartozip_setup.exe - Powered by Reason Core Security