setup.exe

Iqdenwj & co.

The application setup.exe has been detected as a potentially unwanted program by 38 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Iqdenwj & co.

Description:
Zuopzuus

Version:
4.23.4.17

MD5:
98a02ff6e22f6c46c08ccf8f2566088b

SHA-1:
31bfb5ecc52a802e5471bc487b7d592c0b31f1a4

SHA-256:
cc37ee013c946fb00829c1f18d13dff1b48ad2303dfb6fb6c7e9a9c1fc7e77b3

Scanner detections:
38 / 68

Status:
Potentially unwanted

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/25/2024 7:55:36 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Solimba.1
801

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
ASD.Prevention
2013.06.28

Avira AntiVirus
APPL/Solimba.Gen
7.11.61.98

avast!
Win32:PUP-gen [PUP]
2014.9-141126

AVG
AdInstaller.Q
2015.0.3279

Baidu Antivirus
Trojan.MSIL.Solimba
4.0.3.141126

Bitdefender
Gen:Variant.Adware.Solimba.1
1.0.20.1650

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/18355

Comodo Security
Application.Win32.Solimba.a
15261

Dr.Web
Adware.Downware.798
9.0.1.0330

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba
8.14.11.26.04

ESET NOD32
MSIL/Solimba
8.8016

Fortinet FortiGate
Adware/Fam.NB
11/26/2014

F-Prot
W32/Solimba.B.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Adware.Solimba.1
11.2014-26-11_4

G Data
Gen:Variant.Adware.Solimba
14.11.22

IKARUS anti.virus
AdWare.Solimba
t3scan.2.0.3.0

K7 AntiVirus
Unwanted-Program
13.160.8223

Kaspersky
not-a-virus:AdWare.MSIL.Solimba
14.0.0.2889

Malwarebytes
PUP.Offerware
v2014.11.26.04

McAfee
Artemis!395ECAAEE6AD
5600.6935

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
15.0.0.990

NANO AntiVirus
Riskware.Win32.Downware.cruvdx
0.28.0.58101

Norman
Solimba.DIMI
11.20141126

nProtect
Trojan/W32.Agent.178856.B
13.02.15.02

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
AdWare.MSIL.Solimba.c (Not a Virus)
11.14.12.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.26.4

Rising Antivirus
Trojan.Win32.Generic.13FD7DA9
23.00.65.141124

Sophos
DownloadMR
4.93

SUPERAntiSpyware
Trojan.Agent/Gen-Solimba
10215

Trend Micro House Call
TROJ_GEN.RCBOHLU
7.2.330

Trend Micro
TROJ_GEN.RCBCOEK
10.465.26

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
26878

XVirus List
Win32.Detected
2.7.5

File size:
12.7 MB (13,313,600 bytes)

Copyright:
Copyright Seizrsvzmpmgj

Trademarks:
Cmvoqhbovja is a trademark of Ofvhyqpegixw

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

File PE Metadata
Compilation timestamp:
12/4/2012 6:55:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
393216:0kLTQ5g8WQKSUybxV9ETXApAALxwOhplTJ5wvw:0k/Q5/f9V9iwLxp9uY

Entry address:
0x412D

Entry point:
60, F3, 4D, C7, C2, E9, B8, B4, 26, B1, 1D, 8A, DA, 69, D0, 20, 4F, 9C, 86, 40, 73, 02, 8B, C0, E8, 00, 00, 00, 00, 71, 09, B2, F5, 2D, 55, 40, 35, 3B, 87, F6, F6, C5, 6A, F7, C2, 7F, D8, 72, B0, 0F, B6, D7, 75, 06, 69, F6, 4E, A4, 23, F4, FE, C2, 33, F9, 85, F1, 8D, 0D, F9, 8C, 0E, 00, EB, 06, 89, D6, F6, C3, 88, 45, 81, E9, 32, 32, 0E, 00, 87, ED, 03, D9, 85, CA, 35, 8A, 9C, C4, D8, 8A, D0, 81, EB, E5, 08, 00, 00, 5A, 81, FB, F8, 34, 00, 00, 76, 05, 0F, AF, C0, FE, CF, 86, E8, 11, F3, 28, D4, 0F, BF, F2...
 
[+]

Entropy:
7.9995  (probably packed)

Code size:
33.5 KB (34,304 bytes)

Remove setup.exe - Powered by Reason Core Security