setup.exe

Clovermedia SLU

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Clovermedia SLU has been detected as adware by 13 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Clovermedia SLU  (signed and verified)

MD5:
05f2366408d2d119768c9f0d766f21cb

SHA-1:
09c75c8ac781b288a799ab915fd61ae719bfa7b7

SHA-256:
27a8d8ceb12310a7b915bbd65ad1e73996b0a85a0d98aadc650fca223aaf3923

Scanner detections:
13 / 68

Status:
Adware

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/24/2024 9:18:13 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.DomaIQ.B
525

Agnitum Outpost
PUA.DomaIQ
7.1.1

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.150.164

avast!
DomaIQ-CC [PUP]
2014.9-150828

Bitdefender
Application.Bundler.DomaIQ.B
1.0.20.1200

Dr.Web
Trojan.Packed.26772
9.0.1.0240

herdProtect (fuzzy)
2015.8.28.21

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.1510

Malwarebytes
PUP.Optional.BundleInstaller.A
v2015.08.28.09

McAfee
PUP-FJP!4377306C677D
5600.6659

MicroWorld eScan
Application.Bundler.DomaIQ.B
16.0.0.720

Reason Heuristics
PUP.Tuguu.ClovermediaU.Bundler (M)
15.7.26.20

VIPRE Antivirus
Threat.4150696
29396

File size:
480.1 KB (491,656 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/28/2014 1:00:00 AM

Valid to:
3/1/2015 12:59:59 AM

Subject:
CN=Clovermedia SLU, O=Clovermedia SLU, STREET="Aragon 3, D12", L=Adeje, S=Santa Cruz de Tenerife, PostalCode=38670, C=ES

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009737188425E0819038CFB58398A6812A

File PE Metadata
Compilation timestamp:
5/15/2014 11:57:10 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:2gM+lFy9XBu5gmEBipkz+Jix8NB40poIZ2ix0LzjYfbdBcpv9Y0:2qFytBu5kiplJiGDIix4zjNpv9

Entry address:
0x4E24

Entry point:
E8, 2F, 34, 00, 00, E9, 39, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, 58, 03, 43, 00, FF, 15, 6C, D0, 41, 00, 85, C0, 75, 18, 56, E8, 20, 13, 00, 00, 8B, F0, FF, 15, 50, D0, 41, 00, 50, E8, 6B, 13, 00, 00, 59, 89, 06, 5E, 5D, C3, 55, 8B, EC, 56, 8B, 75, 0C, 57, 33, FF, 85, F6, 74, 1B, 6A, E0, 33, D2, 58, F7, F6, 3B, 45, 10, 73, 0F, E8, ED, 12, 00, 00, C7, 00, 0C, 00, 00, 00, 33, C0, EB, 3C, 0F, AF, 75, 10, 53, 8B, 5D, 08, 85, DB, 74, 09, 53, E8, 16, 1B, 00, 00, 59, 8B, F8...
 
[+]

Code size:
109 KB (111,616 bytes)

Remove setup.exe - Powered by Reason Core Security