Setup.exe

Tarma Installer

Tarma Software Research Pty Ltd

The application Setup.exe by Tarma Software Research Pty has been detected as a potentially unwanted program by 3 anti-malware scanners. This is the uninstaller utility registered in the Windows Control Panel for the program Yontoo Layers Client 1.10.01 by Yontoo Technology, Inc..
Publisher:
Tarma Software Research Pty Ltd  (signed and verified)

Product:
Tarma® Installer

Version:
2010.05.03.1118U

MD5:
e08a712ccf3939c60cd0fe3a8b692738

SHA-1:
2948871c5ac1dc8c68761ae0e5e27b05b87d505d

SHA-256:
c164c7f39bb862312baa82594a8d7e17fe2f6c372e8e127faa5c344edb844c39

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 9:04:18 PM UTC  (today)

Scan engine
Detection
Engine version

F-Prot
W32/Adware.B.gen
v6.4.7.1.166

Prevx
High Risk Cloaked Malware
3.0

Reason Heuristics
Adware.Yontoo.TarmaSoftwareResearch.Installer.Meta (M)
15.11.25.15

File size:
221.5 KB (226,816 bytes)

Product version:
5.9.3776

Copyright:
© 1990-2010 Tarma Software Research Pty Ltd

Trademarks:
Tarma® is a registered trademark of Tarma Software Research Pty Ltd

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\tarma installer\{889df117-14d1-44ee-9f31-c5fb5d47f68b}\setup.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
8/4/2009 5:00:00 PM

Valid to:
8/6/2010 4:59:59 PM

Subject:
CN=Tarma Software Research Pty Ltd, OU=DEVELOPMENT, O=Tarma Software Research Pty Ltd, L=Melbourne, S=Victoria, C=AU

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
19F9CC3CA4240408AFB5578FAA4913F1

File PE Metadata
Compilation timestamp:
5/2/2010 6:19:26 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:fT58Ickp9xQftkiDn4X5WORxdoG7itjRY:9mmxotF4XwORxdo7tjRY

Entry address:
0x195A8

Entry point:
E8, FA, FC, FF, FF, E9, 4C, FF, FF, FF, 55, 8B, EC, 83, EC, 10, 56, 57, 8B, FA, 85, FF, 74, 03, 83, 27, 00, 8B, 75, 08, 85, F6, 74, 03, 83, 26, 00, 8D, 45, F0, 50, 6A, 00, 68, 00, 10, 00, 00, 6A, 02, 5A, E8, A0, A7, 00, 00, 85, C0, 74, 0B, 85, F6, 74, 02, 89, 06, 83, C8, FF, EB, 4F, 8B, 45, F0, 8B, 48, 10, 81, F9, 74, 69, 7A, 32, 74, 34, 81, F9, 74, 69, 7A, 33, 74, 2C, 66, 81, 38, 4D, 5A, 75, 17, 81, 78, 24, 74, 73, 6C, 35, 75, 0E, 85, FF, 6A, 02, 5E, 74, 18, 8B, 40, 38, 89, 07, EB, 11, 85, F6, 74, 06, C7...
 
[+]

Entropy:
6.4298

Code size:
144.5 KB (147,968 bytes)

Program Uninstaller
Program name:
Yontoo Layers Client 1.10.01

Display publisher:
Yontoo Technology, Inc.

Display version:
1.10.01

Uninstall string:
C:\PROGRA~3\TARMAI~1\{889DF~1\Setup.exe /remove /q0


Remove Setup.exe - Powered by Reason Core Security