setup-b.exe

Media Viewer alpha 7311

Media Viewer

The application setup-b.exe has been detected as a potentially unwanted program by 28 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. BetterSurf is a program that comes with software bundlers that offer free applications and will add a plugin to Internet Explorer, Firefox, and Chrome which displays advertisements on websites and search engines..
Publisher:
Media Viewer

Product:
Media Viewer alpha 7311

Version:
1.1

MD5:
7b09eb18907d379141acef78bbf1923d

SHA-1:
f92f7ba845fb2e55b4f71ab7565cceb480e938e1

SHA-256:
af1cac1ee9f8e914f909209ce93f1ffa888c85682c670977256031f02471c7a4

Scanner detections:
28 / 68

Status:
Potentially unwanted

Explanation:
Installed with software bundlers that offer free applications or games and adds a plugin to Internet Explorer, Firefox, and Chrome and will display ads as the user browses the Internet, both in websites and on search engine results

Analysis date:
4/19/2024 4:59:06 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BetterSurf.F
1017

AhnLab V3 Security
14.04.24

Avira AntiVirus
ADWARE/Adware.Gen
7.11.137.70

avast!
Win32:Adware-gen [Adw]
2014.9-140424

AVG
Skodna.Generic_r
2015.0.3495

Bitdefender
Adware.BetterSurf.F
1.0.20.570

Comodo Security
Application.Win32.AdWare.BetterSurf.B
17936

Dr.Web
Trojan.Siggen6.9071
9.0.1.0114

Emsisoft Anti-Malware
Adware.BetterSurf
8.14.04.24.12

ESET NOD32
Win32/AdWare.BetterSurf (variant)
8.9547

F-Secure
Adware.BetterSurf.F
11.2014-24-04_5

G Data
Adware.BetterSurf
14.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

K7 AntiVirus
Unwanted-Program
13.176.11451

Kaspersky
not-a-virus:AdWare.Win32.BetterSurf
14.0.0.3970

Malwarebytes
PUP.Optional.MediaViewer.A
v2014.04.24.12

McAfee
Artemis!7B09EB18907D
5600.7151

Microsoft Security Essentials
1.10302

MicroWorld eScan
Adware.BetterSurf.F
15.0.0.342

NANO AntiVirus
Riskware.Win32.BetterSurf.crmvtp
0.28.0.58394

nProtect
Adware.BetterSurf.F
14.03.15.01

Panda Antivirus
Generic Malware
14.04.24.12

Rising Antivirus
PE:Malware.BetterSurf!6.11BF
23.00.65.14422

Sophos
BetterSurf
4.98

Trend Micro House Call
TROJ_SPNR.0BBO14
7.2.114

Trend Micro
TROJ_SPNR.0BBO14
10.465.24

Vba32 AntiVirus
AdWare.BetterSurf
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
27420

File size:
944.8 KB (967,438 bytes)

Product version:
1.1

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\setup-b.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:FmtVk0puG4GfJMRo0dHvZjZLGFSGzBg8EtbQdBZoMJC0lHKZjZLJUeGzFg8DT6Gs:FmTuG4Gxuo0fZLGFNfB6oC0QZLJUVqV

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup-b.exe - Powered by Reason Core Security