setup.exe

Creative Island Media, LLC

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Creative Island Media has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address update.betterxperience.com on port 80 using the HTTP protocol.
Publisher:
Creative Island Media, LLC  (signed and verified)

MD5:
56e84d0a5d3bd1b3ccaea5c08d39c4cd

SHA-1:
19f5e37430ad0684850bb047ab5c2b8ff4c716fc

SHA-256:
ee1cb77968ae864c649bf1147e1c71555e2d113da45ba8d487d36b9fcdd0ba5c

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/23/2024 12:52:00 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:BHO-AMO [PUP]
2014.9-140910

Dr.Web
Adware.Plugin.128
9.0.1.0253

ESET NOD32
Win32/ExFriendAlert (variant)
8.9151

Malwarebytes
PUP.Optional.SearchDonkey.A
v2014.09.10.07

Reason Heuristics
PUP.Installer.CreativeIslandMedia.F
14.9.10.6

Trend Micro House Call
TROJ_GEN.F47V1125
7.2.253

VIPRE Antivirus
SearchDonkey
24190

File size:
3.7 MB (3,839,808 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/21/2013 2:00:00 AM

Valid to:
5/22/2014 1:59:59 AM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
6/6/2009 11:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:fKo3DBK6mvPaRcc/HQ91m3O5ZBfYTJggRGE4OwpnlrEieHmzVOEeWjOXZBEqk:fTTM1XaK9KOnMqgUXdllrEihVOEHOpW

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9886

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

Remove setup.exe - Powered by Reason Core Security