Setup.exe

InstallShield

telegate MEDIA AG

The executable Setup.exe has been detected as malware by 40 anti-virus scanners. The program is a setup application that uses the InstallShield Setup installer. This is the uninstaller utility registered in the Windows Control Panel for the program klickTel Routenplaner Deutschland und Europa Sommer 2012 by telegate MEDIA AG.
Publisher:
Acresso Software Inc.  (signed by telegate MEDIA AG)

Product:
InstallShield

Description:
Setup.exe

Version:
15.0.498

MD5:
e4410f66c7cb1d0eaf1d76f1cf2817ae

SHA-1:
381dc75a1b2a160df4acba07f14def9291428201

SHA-256:
587be06763b557275aab9ff6b5ae581fb7b013d4f5f0fd10fb47fac47307190e

Scanner detections:
40 / 68

Status:
Malware

Analysis date:
4/19/2024 5:36:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Runouce.B@mm
809

Agnitum Outpost
I-Worm.Chir.B
7.1.1

AhnLab V3 Security
Win32/ChiHack.6652
2014.07.05

Avira AntiVirus
W32/Chir.B
7.11.30.172

avast!
Win32:Oncer
2014.9-141117

AVG
Win32/Chir.B@mm
2015.0.3287

Baidu Antivirus
Virus.Win32.Runouce.$a
4.0.3.141117

Bitdefender
Win32.Runouce.B@mm
1.0.20.1605

Bkav FE
W32.ChirBPE
1.3.0.4959

Clam AntiVirus
WIN.Worm.Brontok
0.98/21411

Comodo Security
EmailWorm.Win32.Runonce.~v001
18771

Dr.Web
Win32.Runonce.6652
9.0.1.0321

Emsisoft Anti-Malware
Win32.Runouce.B@mm
8.14.11.17.05

ESET NOD32
Win32/Chir.B virus
8.7.0.302.0

Fortinet FortiGate
W32/Chir.B@mm
11/17/2014

F-Prot
W32/Thecid.B@mm
v6.4.6.5.141

F-Secure
Win32.Runouce.B@mm
11.2014-17-11_2

G Data
Win32.Runouce.B@mm
14.11.24

IKARUS anti.virus
Email-Worm.Win32.Runouce
t3scan.1.6.1.0

K7 AntiVirus
EmailWorm
13.180.12626

Kaspersky
Email-Worm.Win32.Runouce
14.0.0.2931

Malwarebytes
Virus.Chir
v2014.11.17.05

McAfee
W32/Chir.b@MM
5600.6943

Microsoft Security Essentials
Threat.Undefined
1.177.1657.0

MicroWorld eScan
Win32.Runouce.B@mm
15.0.0.963

NANO AntiVirus
Virus.Win32.Runouce.bxafx
0.28.0.60577

Norman
Malware
11.20141117

nProtect
Win32.Runouce.B@mm
14.07.04.01

Panda Antivirus
W32/Chir.B
14.11.17.05

Qihoo 360 Security
Virus.Win32.CNHacker.C
1.0.0.1015

Quick Heal
W32.Runouce.B
11.14.14.00

Rising Antivirus
PE:Worm.ChineseHacker-2!23772
23.00.65.141115

Sophos
W32/Chir-A
4.98

Total Defense
Win32/Chir.B
37.0.11039

Trend Micro House Call
PE_Chir.B
7.2.321

Trend Micro
PE_Chir.B
10.465.17

Vba32 AntiVirus
Virus.Win32.Chur.A
3.12.26.3

VIPRE Antivirus
Threat.219451
29708

ViRobot
Win32.Chir.B
2011.4.7.4223

Zillya! Antivirus
Worm.Runouce.Win32.2
2.0.0.1845

File size:
390.2 KB (399,536 bytes)

Product version:
15.0

Copyright:
Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
InstallShield Setup

Language:
English (United States)

Common path:
C:\Program Files\installshield installation information\{f7436291-e071-4217-8656-011179a789d3}\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
11/17/2010 4:15:52 PM

Valid to:
11/17/2013 4:15:49 PM

Subject:
E=mustafa.oezen@telegate.com, CN=telegate MEDIA AG, O=telegate MEDIA AG, L=Essen, S=Nordrhein-Westfalen, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012C5A7B6E94

File PE Metadata
Compilation timestamp:
5/10/2008 5:39:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:ZGWK9s2n1sDEo7SUknwoD6AaeICSj7kEoeB0PFn0wccccccccu:Z9ysTOnKt7owT

Entry address:
0x21EE4

Entry point:
55, 8B, EC, 6A, FF, 68, F0, A2, 44, 00, 68, 60, 49, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, FC, 92, 44, 00, 33, D2, 8A, D4, 89, 15, D0, 8B, 45, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, CC, 8B, 45, 00, C1, E1, 08, 03, CA, 89, 0D, C8, 8B, 45, 00, C1, E8, 10, A3, C4, 8B, 45, 00, 6A, 01, E8, A4, 17, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 98, 14, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
288 KB (294,912 bytes)

Program Uninstaller
Program name:
klickTel Routenplaner Deutschland und Europa Sommer 2012

Display publisher:
telegate MEDIA AG

Display version:
1.00.0000

Uninstall string:
"C:\Program Files (x86)\InstallShield Installation Information\{F7436291-E071-4217-8656-011179A789D3}\SETUP.EXE" -runfromtemp -l0x0007 -removeonly


Remove Setup.exe - Powered by Reason Core Security