safeguardsetup.exe

SafeGuard

Alerts LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application safeguardsetup.exe by Alerts has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from i.vertitechnologygroup.com.
Publisher:
Alerts LLC  (signed and verified)

Product:
SafeGuard

Version:
1.0.2.25

MD5:
26c9b073794a865a5bbff8278c7d9c0c

SHA-1:
2f035a094f2a11783da6e92b1a5004c24f590e6c

SHA-256:
d9388d51de5332571d52aa3cbefc5582254552b76c2fc287fccfa779fa0654a4

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
4/24/2024 10:19:20 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.Agent
7.1.1

Dr.Web
Adware.Plugin.962
9.0.1.0254

ESET NOD32
Win32/Verti.L potentially unwanted
9.11411

Fortinet FortiGate
Riskware/Verti
9/11/2015

K7 AntiVirus
Trojan
13.202.15452

McAfee
Artemis!26C9B073794A
5600.6646

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Weather.Alerts.Installer (M)
15.9.11.2

Sophos
Generic PUA GP
4.98

Trend Micro House Call
TROJ_GEN.R02SC0OCU15
7.2.254

Trend Micro
TROJ_GEN.R02SC0OCU15
10.465.11

VIPRE Antivirus
Trojan.Win32.Generic
38964

File size:
534.1 KB (546,904 bytes)

Product version:
1.0.2.25

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\safeguardsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/4/2014 8:00:00 PM

Valid to:
6/5/2015 7:59:59 PM

Subject:
CN=Alerts LLC, O=Alerts LLC, STREET="101 Colorado St #2309", L=Austin, S=TX, PostalCode=78701, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A4FE74573C3AAF1867F4DF866A77B161

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:rgEneBg0aIz0iu2C7gZBmyqbnenc6Hx72aorzc:rgyeBbaq0iulk4b2c6Ryagzc

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9545

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file safeguardsetup.exe has been seen being distributed by the following URL.

Remove safeguardsetup.exe - Powered by Reason Core Security