setup.exe

Time Lapse Solutions

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Time Lapse Solutions has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to AVG, this software downloads additional adware offers during setup. It is also typically executed from the user's temporary directory.
Publisher:
Time Lapse Solutions  (signed and verified)

MD5:
c7a9fcecce3b59dae7e3b61542e7f2b7

SHA-1:
2a2d63e27c85d63317800200c5d47bbe90680c47

SHA-256:
9851b9c03398df695592a9ad6a388f14f0672ac486d8e4e4411aa9901a81dbbf

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/24/2024 8:32:51 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.206.68

AVG
Potentially harmful program Downloader.CBD
2014.0.4253

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.1521

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
multiple threats
7.0.302.0

Malwarebytes
PUP.Optional.ZombieNews.A
v2015.02.01.04

NANO AntiVirus
Riskware.Win32.Yontoo.dmgkuc
0.30.0.65070

Reason Heuristics
PUP.Installer.Injekt
15.2.1.4

VIPRE Antivirus
Threat.4784449
36694

File size:
4.5 MB (4,689,608 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/26/2015 12:00:00 AM

Valid to:
4/27/2016 12:59:59 AM

Subject:
CN=Time Lapse Solutions, O=Time Lapse Solutions, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
088D68E27F37630FE9E23AD19AC872B3

File PE Metadata
Compilation timestamp:
6/6/2009 10:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:MyzF5yEXDaWKTizoUXnfd3oN6QYKG0ONFEu5GxF5yU:Myz/JdKT8nF3ogDBgx/7

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9848

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Remove setup.exe - Powered by Reason Core Security