setup.exe

The application setup.exe has been detected as a potentially unwanted program by 19 anti-malware scanners.
Description:
Uninstall.exe

Version:
1.5.0.0

MD5:
22a12021f3ce13802d0ddfd794d5842e

SHA-1:
04a3475fa83b9708e019a8ec5b8a8e222b94c16b

SHA-256:
e34c01ee40b3bb883f40ac43d38f14d2751d4c6b6b8b9ff128bcc61d99c6a5e5

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 3:07:16 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.172245
5643196

AhnLab V3 Security
PUP/Win32.Goobzo
2015.05.20

avast!
GenMaliciousA-IJB [PUP]
150414-0

AVG
Generic36
2016.0.3133

Baidu Antivirus
PUA.Win32.SBWatchman
4.0.3.15421

Bitdefender
Gen:Variant.Graftor.172245
1.0.20.555

Dr.Web
Adware.Searcher.2794
9.0.1.0111

Emsisoft Anti-Malware
Gen:Variant.Graftor.172245
9.0.0.4799

ESET NOD32
Win32/SBWatchman.E potentially unwanted (variant)
9.11651

F-Secure
Gen:Variant.Graftor.172245
5.13.68

G Data
Gen:Variant.Graftor.172245
15.4.25

IKARUS anti.virus
PUA.SBWatchman
t3scan.1.8.9.0

McAfee
GenericR-DCM!FC9A36B638C8
5600.6789

MicroWorld eScan
Gen:Variant.Graftor.172245
16.0.0.333

NANO AntiVirus
Riskware.Nsis.Downloader.dpmcpm
0.30.8.659

Panda Antivirus
Trj/Genetic.gen
15.04.21.02

Qihoo 360 Security
HEUR/QVM41.2.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
15.4.21.2

VIPRE Antivirus
Threat.4150696
39354

File size:
529 KB (541,696 bytes)

Product version:
1.5.0.0

Copyright:
Copyright (C) 2014

Original file name:
UnInstall.exe

File type:
Executable application (Win32 EXE)

Language:
Hebrew (Israel)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

File PE Metadata
Compilation timestamp:
4/3/2015 5:55:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:m9svRgBo7Gq0gkfJTLo6dvxdhc33MYAvS:m9sqCGl9fJTLooLS31

Entry address:
0x1F3C7

Entry point:
E8, DB, 36, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 4E, 25, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, 50, DC, 43, 00, 74, 12, 8B, 0D, 08, DA, 43, 00, 85, 48, 70, 75, 07, E8, 4E, 41, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 10, D9, 43, 00, 74, 16, 8B, 46, 08, 8B, 0D, 08, DA, 43, 00, 85, 48, 70, 75, 08, E8, AD, 39, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A...
 
[+]

Entropy:
7.0250

Code size:
182 KB (186,368 bytes)

Remove setup.exe - Powered by Reason Core Security