Setup.exe

The file Setup.exe has been detected as a potentially unwanted program by 30 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
MD5:
94afd9e5b4cffeebbfa1a6c765c3253c

SHA-1:
516e2cfb701eb8b862cd0ac4ddd53192367dc879

SHA-256:
98d65ec0a052823b30cadfc06b8625e6e8f5b5d22ac37106f03d123acffd60ac

Scanner detections:
30 / 68

Status:
Potentially unwanted

Explanation:
The software cotains keystroke monitoring/logging capablities which may or may not be installed without the user's knowledge.

Analysis date:
4/19/2024 9:57:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Keylogger.PUX
524

Agnitum Outpost
RiskWare.Keylog
7.1.1

Avira AntiVirus
SPR/StealthKeylog.1
3.6.1.96

avast!
Win32:Spyware-gen [Spy]
2014.9-150830

AVG
Logger
2016.0.3002

Bitdefender
Application.Keylogger.PUX
1.0.20.1210

Comodo Security
UnclassifiedMalware
22025

Dr.Web
Program.SystemKey.13
9.0.1.0242

Emsisoft Anti-Malware
Application.Keylogger.PUX
8.15.08.30.01

ESET NOD32
Win32/KeyLogger.StealthKeylogger
9.11585

Fortinet FortiGate
Riskware/Amplusnet
8/30/2015

F-Prot
W32/Spyware.ASF
v6.4.7.1.166

F-Secure
Application.Keylogger.PUX
11.2015-30-08_1

G Data
Application.Keylogger.PUX
15.8.25

IKARUS anti.virus
Trojan-Dropper.Agent
t3scan.1.8.9.0

K7 AntiVirus
Trojan
13.203.15823

Kaspersky
not-a-virus:Monitor.Win32.Amplusnet
14.0.0.1505

McAfee
Generic PUP.x
5600.6658

Microsoft Security Essentials
MonitoringTool:Win32/StealthKeylogger
1.1.11602.0

MicroWorld eScan
Application.Keylogger.PUX
16.0.0.726

NANO AntiVirus
Riskware.Win32.Amplusnet.bodzm
0.30.24.1357

Norman
Suspicious_Gen2.PAYSP
11.20150830

nProtect
Abuse-Worry/W32.Amplusnet.3662552
15.05.06.01

Panda Antivirus
Trj/CI.A
15.08.30.01

Qihoo 360 Security
Win32/Virus.Monitor.015
1.0.0.1015

Sophos
Generic PUA MA
4.98

Trend Micro House Call
TROJ_CINMUS.IY
7.2.242

Trend Micro
TROJ_CINMUS.IY
10.465.30

VIPRE Antivirus
Stealth KeyLogger
39958

ViRobot
Monitor.Amplusnet.3662552[h]
2014.3.20.0

File size:
3.5 MB (3,662,552 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
11/20/2008 6:28:21 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:SQcg2+ad+bLff0l8ASb9Uiw8UhxFCXeWpIBafgFR9yVTgcTKe3+FRhm5c7GOO:htad+Ml8599UhCVOn9iTN+Fij

Entry address:
0x30E3

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 58, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, 23, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 90, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 4C, 91, 40, 00, 68, 60, E3, 42, 00, E8, DA, 27, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, C8, 27, 00, 00...
 
[+]

Entropy:
7.9970

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove Setup.exe - Powered by Reason Core Security