setup-a.exe

Media Viewer alpha 175

Media Viewer

The application setup-a.exe has been detected as a potentially unwanted program by 28 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
Media Viewer

Product:
Media Viewer alpha 175

Version:
1.1

MD5:
4ea43e57140d2e8d8d175de5642bee50

SHA-1:
abdefedcb9a02cbfd5d8bb639f40ebb06a5a7bba

SHA-256:
c7a151a03d45b2cae11af0125f80c0749912a259540b5f03fb7d2e8bbfabbd62

Scanner detections:
28 / 68

Status:
Potentially unwanted

Explanation:
Installed with software bundlers that offer free applications or games and adds a plugin to Internet Explorer, Firefox, and Chrome and will display ads as the user browses the Internet, both in websites and on search engine results

Analysis date:
4/23/2024 9:28:08 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BetterSurf.F
928

Avira AntiVirus
ADWARE/Adware.Gen
7.11.133.196

avast!
Win32:Adware-gen [Adw]
2014.9-140722

AVG
Skodna.Generic_r
2015.0.3406

Baidu Antivirus
4.0.3.14722

Bitdefender
Adware.BetterSurf.F
1.0.20.1015

Dr.Web
Adware.BetterSurf.597
9.0.1.0203

Emsisoft Anti-Malware
Adware.BetterSurf
8.14.07.22.04

ESET NOD32
Win32/AdWare.BetterSurf (variant)
8.9476

Fortinet FortiGate
Adware/BetterSurf
7/22/2014

F-Secure
Adware.BetterSurf.F
11.2014-22-07_3

G Data
Adware.BetterSurf
14.7.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Adware
13.176.11278

Kaspersky
not-a-virus:AdWare.Win32.BetterSurf
14.0.0.3524

Malwarebytes
PUP.Optional.Amonetize.A
v2014.07.22.04

McAfee
Artemis!4EA43E57140D
5600.7062

Microsoft Security Essentials
1.10302

MicroWorld eScan
Adware.BetterSurf.F
15.0.0.609

NANO AntiVirus
Riskware.Win32.BetterSurf.csovck
0.28.0.58101

nProtect
Adware.BetterSurf.F
14.02.26.01

Panda Antivirus
Generic Malware
14.07.22.04

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.BetterSurf!6.11BF
23.00.65.14720

Sophos
Generic PUA EM
4.98

Trend Micro
TROJ_SPNR.0BBO14
10.465.22

Vba32 AntiVirus
AdWare.BetterSurf
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
26878

File size:
944.8 KB (967,449 bytes)

Product version:
1.1

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\setup-a.exe

File PE Metadata
Compilation timestamp:
12/6/2009 6:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:fZoVsG4GfJMRo0dHvZjZLGFSGzBg8EtbQdiYMru0tHQZjZLdYuGzHg89007IaRb:fZmsG4Gxuo0fZLGFNflWu0GZLdYrmIIc

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9897

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup-a.exe - Powered by Reason Core Security