setup.exe

WEB PICK - INTERNET HOLDINGS LTD

This is a WebPick installer that bundles (with very minimal user consent) a number of adware browser extensions using the JustPlug.it browser framework. The application setup.exe, “Installer for SoftSafe” by WEB PICK - INTERNET HOLDINGS has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex (Tarma) installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
SoftSafe  (signed by WEB PICK - INTERNET HOLDINGS LTD)

Product:
SoftSafe

Description:
Installer for SoftSafe

Version:
2013.2.28.1540

MD5:
70efb96aeac935ffe1bd402587747041

SHA-1:
64b7f6bca3f1f9568cc716225958140d517c2db8

SHA-256:
f53a1cdf0c693d71234125d37f2ce7be0fda6be457425ae201e59198af598548

Scanner detections:
31 / 68

Status:
Adware

Explanation:
Uses the InstalleRex from WebPick Internet Holdings to install bundled add-ons including toolbars and other web browser extensions.

Analysis date:
4/20/2024 8:02:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.458955
369

Agnitum Outpost
Trojan.Rogue
7.1.1

AhnLab V3 Security
Adware/Win32.StartPage
2015.01.21

Avira AntiVirus
TR/Rogue.8748011
7.11.203.160

avast!
Win32:InstalleRex-AG [PUP]
2014.9-160201

AVG
Skodna.Pick
2017.0.2847

Bitdefender
Adware.Generic.458955
1.0.20.160

Bkav FE
W32.FamVT.AntiFWK.Trojan
1.3.0.6379

Clam AntiVirus
Win.Adware.404217
0.98/19745

Comodo Security
Application.Win32.InstalleRex.KG
20785

Dr.Web
Trojan.WebPick.4
9.0.1.032

Emsisoft Anti-Malware
Adware.Generic.458955
8.16.02.01.01

ESET NOD32
Win32/InstalleRex.E potentially unwanted application
10.7.0.302.0

Fortinet FortiGate
Riskware/InstalleRex
2/1/2016

F-Prot
W32/InstallRex.B
v6.4.6.5.141

F-Secure
Adware.Generic.458955
11.2016-01-02_2

G Data
Adware.Generic.458955
16.2.24

K7 AntiVirus
Unwanted-Program
13.191.14703

Kaspersky
not-a-virus:HEUR:Downloader.Win32.AdLoad
14.0.0.730

Malwarebytes
PUP.Optional.InstalleRex
v2016.02.01.01

MicroWorld eScan
Adware.Generic.458955
17.0.0.96

NANO AntiVirus
Riskware.Win32.Downware.cspeey
0.30.0.64812

Norman
Adware.Generic.458955
11.20160201

nProtect
Trojan/W32.StartPage.287784
14.11.10.01

Panda Antivirus
PUP/TSUploader
16.02.01.01

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
Adware.WebPick.Installer (M)
16.2.1.1

Rising Antivirus
PE:Trojan.DL.Win32.AntiFW.a!1075355932
23.00.65.16130

Sophos
PUA 'InstallRex'
59

Vba32 AntiVirus
Downware.TSU
3.12.26.3

Zillya! Antivirus
Trojan.Agent.Win32.369901
2.0.0.2041

File size:
280.5 KB (287,272 bytes)

Product version:
1.0

Copyright:
Copyright © 2012 SoftSafe

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
WebPick InstalleRex (Tarma)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/25/2012 1:00:00 AM

Valid to:
3/23/2013 12:59:59 AM

Subject:
CN=WEB PICK - INTERNET HOLDINGS LTD, O=WEB PICK - INTERNET HOLDINGS LTD, L=Ramat Hasharon, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
69BA3E5E7FA6543891BD41AC3F494F15

File PE Metadata
Compilation timestamp:
2/4/2013 10:49:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:Rr+yI5RxWBDg7V0eXze6OvA48UEJFeiCLxNw4QC8cdo:Rr+yI3sBDJejgP0JHYz1f9o

Entry address:
0x14DB

Entry point:
55, 8B, EC, 81, EC, 2C, 06, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, DC, FB, FF, FF, 89, 5D, F4, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 70, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 6C, 30, 40, 00, FF, 15, 68, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 64, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, D4, F9, FF, FF, 50, 53, FF, 15, 60, 30, 40, 00, 85, C0, 75, 41, FF, 15, 5C, 30, 40, 00, 83, F8, 78, 75, 1A, 68, A8, 32, 40, 00, E8, 43, FB, FF, FF...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=56480432&publisher_id=648&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=169441296&external_id=0&session_id=338882592&hardware_id=395363024&installer_file_name=setup

Remove setup.exe - Powered by Reason Core Security