setup.exe

File

VerIfieD software snb

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by VerIfieD software snb has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:
VerIfieD software snb  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
8af184c6b3f115953839f5f508b444cb

SHA-1:
40042f1a4bf59c795985a321a879dce61826ebe3

SHA-256:
41e71f68552073857f0526a3ed1462d9f6359f1deb13d1b1850f29feb6883ead

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
9/17/2025 6:30:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Trojan.Generic.13116234
6207143

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.04.04

avast!
PUP-gen [PUP]
150319-0

AVG
Downloader
2016.0.3150

Bitdefender
Dropped:Trojan.Generic.13116234
1.0.20.470

Dr.Web
Trojan.DownLoad3.36217
9.0.1.094

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
4/4/2015

F-Secure
Dropped:Trojan.Generic.13116234
11.2015-04-04_7

G Data
Dropped:Trojan.Generic.13116234
15.4.25

McAfee
Artemis!3FD1ADC4E832
5600.6806

MicroWorld eScan
Dropped:Trojan.Generic.13116234
16.0.0.282

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Sophos
Generic PUA BB
4.98

Trend Micro House Call
Suspici.593F1237
7.2.94

VIPRE Antivirus
Threat.4150696
38882

File size:
1.1 MB (1,101,192 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Apr03-055017-eb7458e6-268a-48e6-af30-5bfa983a5e10.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/31/2015 8:00:00 PM

Valid to:
1/27/2016 6:59:59 PM

Subject:
CN=VerIfieD software snb, O=VerIfieD software snb, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
38FEDA1FC39FD50426002D9E7A0F866F

File PE Metadata
Compilation timestamp:
4/3/2015 1:50:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:1Miy4IadS4ms5I6e66fEheKhBskD8gVEA/nqd746QnI9uvaWdwTmALdfbfroaDx:1bSaE4mvt/g7VEUqa6Qn5bwxdzzow

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove setup.exe - Powered by Reason Core Security