Setup.exe

The file Setup.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
MD5:
4491f8845e727e6b8176fa3472f5499a

SHA-1:
2d6c90fc7deb3002875a1081f98efd083ef4f1e4

SHA-256:
0eac414b3916d725fc8e976f68870ea56757ad9f093ffebbcc5034818254269f

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/7/2024 5:38:15 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
3.6.1.96

Baidu Antivirus
PUA.Win32.Addrop.InstallCore
4.0.3.15520

ESET NOD32
Win32/TrojanDropper.Addrop
9.11530

herdProtect (fuzzy)
2015.7.26.3

K7 AntiVirus
Trojan
13.203.15829

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.18995950!412703056
23.00.65.15724

Sophos
Generic PUA IP
4.98

Trend Micro House Call
Suspicious_GEN.F47V0425
7.2.140

File size:
939.2 KB (961,745 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:uoL/AF11t5PqbEDUCWroUhbXwyv8x5YCZq72VKk1GP87Gre4lKl:uu/6rtFqbVoUhbXws8xiHCFh7Gy4Q

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.7553

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security