Setup.exe

The file Setup.exe has been detected as a potentially unwanted program by 14 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
MD5:
aa7c716f074db6d63b134df05cc793c4

SHA-1:
3ce24199d714680e229f97a6984750e16ec5704f

SHA-256:
5055be2ac117ff45db26fef5080a9e10be019a36575c0bb69b528bcaa2a51fc4

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Analysis date:
4/25/2024 4:13:13 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.DomaIQ
2015.03.31

avast!
DomaIQ-DF [PUP]
150319-1

AVG
Adware DomaIQ.BB
2014.0.4311

Clam AntiVirus
Win.Adware.Domaiq-21
0.98/21511

Dr.Web
Trojan.DownLoader9.45575
9.0.1.05190

ESET NOD32
Win32/DomaIQ.BA potentially unwanted application
7.0.302.0

Fortinet FortiGate
Adware/Lollipop
3/30/2015

G Data
Win32.Application.DomalQ
15.3.25

Kaspersky
not-a-virus:AdWare.Win32.Lollipop
15.0.0.543

NANO AntiVirus
Riskware.Win32.Lollipop.cvvfxj
0.30.8.659

Reason Heuristics
Threat.Win.Reputation.IMP
15.3.30.22

Sophos
DomainIQ pay-per install
4.98

Vba32 AntiVirus
BScope.Downware.DomaIQ
3.12.26.3

Zillya! Antivirus
Adware.DomaIQ.Win32.233
2.0.0.2122

File size:
138.2 KB (141,521 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
3/10/2014 8:25:44 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:x4ad9LQqwcT0P5JOVhfcqdCShtM8irfr66XMZcLFCClOLP:Ou9LQqwcT8KcLUCYL

Entry address:
0x326B

Entry point:
E8, 51, 44, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B, 4C, 24, 04, 2B...
 
[+]

Entropy:
6.4123

Code size:
58 KB (59,392 bytes)

Remove Setup.exe - Powered by Reason Core Security