setup.exe

Bundlore LTD

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe, “Any Media Converter setup” by Bundlore has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. The file has been seen being downloaded from dec.pcvideosfreedownload.com.
Publisher:
Any Media Converter  (signed by Bundlore LTD)

Product:
Any Media Converter

Description:
Any Media Converter setup

Version:
1.14

MD5:
49d04ef7b78bc2cbd483f01174a12844

SHA-1:
5c69ab981876e983964b89dffdb4072eb86bab7a

SHA-256:
0494b6ceb52a42bdf54cd72e688ca4738cb2bf60856f62734442ba36cfa6e67e

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 1:13:48 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInstaller.Bundlor
2016.0.3222

Dr.Web
Adware.Downware.514
9.0.1.022

ESET NOD32
Win32/Toolbar.Conduit
9.11056

G Data
Win32.Adware.Conduit
15.1.24

IKARUS anti.virus
PUA.Bundlore
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.191.14720

Norman
Bundlore.CERT
11.20150122

Reason Heuristics
PUP.Installer.Bundlore
15.1.22.10

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Wajam
36876

File size:
602.6 KB (617,048 bytes)

Copyright:
© Any Media Converter (Converter_I136_AUTO_NICE_SIGNED_WITHPOST)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/5/2012 2:00:00 AM

Valid to:
7/6/2014 1:59:59 AM

Subject:
CN=Bundlore LTD, O=Bundlore LTD, STREET=Beit Oved 9, L=Tel Aviv, S=Israel, PostalCode=67211, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0C7A8094C56AAFE39F3CA37C7F65AC84

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:PuiSWa5+BmiQoJA3Zy5Ui9ojMK0Vs/AcOHBploErlPQMbKz4Qavr2zwj4PjSwd5p:PuiJBSo63MJoIBisHzVQMmMBr2zsF+t

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security