setup.dll

Install Dynamic Link Library

Pinball Corporation.

This is a component for the Pinball ad-supported platform which may deliver advertisemenst to the web browser in the form of banner and text ads. The module setup.dll, “Install Dynamic Link Library” by Pinball has been detected as adware by 40 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Zango, Inc.  (signed by Pinball Corporation.)

Product:
Install Dynamic Link Library

Description:
Install Dynamic Link Library

Version:
10.0.622.0

MD5:
1ec8031bf74094d2524d62881a77e0f8

SHA-1:
8df3114f46fe3d45824b97ba6bc42af6106f779d

SHA-256:
0fcff300a222bbe4a5dbba27378f70be0c5bed0d18eb9857cfc1ac611d93e0ba

Scanner detections:
40 / 68

Status:
Adware

Analysis date:
4/19/2024 6:35:37 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.gu9@Rmk!Oani
363

Agnitum Outpost
Adware.Shopper
7.1.1

AhnLab V3 Security
Adware/Win32.Shopper
2014.09.24

Avira AntiVirus
ADSPY/AdSpy.Gen
7.11.160.254

avast!
Win32:HotBar-CJ [PUP]
2014.9-160207

AVG
Skodna.Generic_r.R
2017.0.2841

Baidu Antivirus
Adware.Win32.HotBar
4.0.3.1627

Bitdefender
Gen:Adware.Heur.gu9@Rmk!Oani
1.0.20.190

Clam AntiVirus
Suspect.W32.AdInstall
0.98/21411

Comodo Security
ApplicUnwnt.Win32.AdWare.HotBar.DE
18866

Dr.Web
Adware.Zango.184
9.0.1.038

Emsisoft Anti-Malware
Gen:Adware.Heur.gu9@Rmk!Oani
8.16.02.07.01

ESET NOD32
Win32/Adware.HotBar (variant)
10.10102

Fortinet FortiGate
Adware/PlatriumSA
2/7/2016

F-Prot
W32/HotBar.N.gen
v6.4.7.1.166

F-Secure
Gen:Adware.Heur.gu9@Rmk!Oani
11.2016-07-02_1

G Data
Gen:Adware.Heur.gu9@Rmk!Oani
16.2.24

IKARUS anti.virus
not-a-virus:AdWare.Win32.HotBar
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.180.12747

Kaspersky
not-a-virus:AdWare.Win32.HotBar
14.0.0.700

Malwarebytes
Adware.Seekmo
v2016.02.07.01

McAfee
Adware-HotBar.g
5600.6497

Microsoft Security Essentials
Adware:Win32/Hotbar
1.10802

MicroWorld eScan
Gen:Adware.Heur.gu9@Rmk!Oani
17.0.0.114

NANO AntiVirus
Riskware.Win32.HotBar.fprzg
0.28.2.60881

Norman
Gen:Adware.Heur.gu9@RawX9sci
11.20160207

nProtect
Trojan-Clicker/W32.HotBar.99632.B
14.09.23.01

Qihoo 360 Security
HEUR/Malware.QVM29.Gen
1.0.0.1015

Quick Heal
AdWare.Hotbar.r5 (Not a Virus)
2.16.14.00

Reason Heuristics
PUP.Pinball.PinballCorporation.Installer (M)
16.2.7.1

Rising Antivirus
PE:Trojan.Win32.Generic.1274BC40!309640256
23.00.65.16205

Sophos
ClickPotato Installer
4.98

SUPERAntiSpyware
Adware.180solutions/Seekmo/Zango
9339

Total Defense
Win32/Zango.Pinball[HOTBAR]
37.0.11061

Trend Micro House Call
TROJ_SPNR.0BL711
7.2.38

Trend Micro
TROJ_SPNR.0BL711
10.465.07

Vba32 AntiVirus
AdWare.HotBar
3.12.26.3

VIPRE Antivirus
Pinball Corporation.
31316

ViRobot
Backdoor.Win32.S.Agent.99632.A
2011.4.7.4223

Zillya! Antivirus
Adware.HotBar.Win32.970
2.0.0.1859

File size:
97.3 KB (99,632 bytes)

Product version:
10.0.622.0

Copyright:
Copyright © 2006-2009 Pinball Corporation. All rights reserved.

Original file name:
Install.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/19/2009 1:00:00 AM

Valid to:
5/20/2011 12:59:59 AM

Subject:
CN=Pinball Corporation., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Pinball Corporation., L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4FEAB55730A755A456FE6C18A4791C1A

File PE Metadata
Compilation timestamp:
11/16/2010 8:44:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
1536:z7A1Dk56MGOH8dJnShEQ5wGN05CWy0/2PM/JXDakB+Y5pvmg6M+cE:QGA9QH+X15pvQ

Entry address:
0x3F14

Entry point:
83, 7C, 24, 08, 01, 75, 05, E8, 5B, 60, 00, 00, FF, 74, 24, 04, 8B, 4C, 24, 10, 8B, 54, 24, 0C, E8, ED, FE, FF, FF, 59, C2, 0C, 00, CC, CC, CC, 68, C0, 32, 00, 10, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 60, 20, 01, 10, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 51, 53, 55...
 
[+]

Entropy:
5.7925

Code size:
52 KB (53,248 bytes)

Remove setup.dll - Powered by Reason Core Security