setup.exe

The application setup.exe has been detected as a potentially unwanted program by 25 anti-malware scanners. The program is a setup application that uses the Self-extracting archive installer, however the file is not signed with an authenticode signature from a trusted source. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
MD5:
c135824868efb4fa460d731230cef1b7

SHA-1:
65a039a7eb03f3fc304ae99775b5b84e54496df3

SHA-256:
3adbfa3475b0c44d5d9be4e27f9b9133734d52dae8ed3475f77f1cd879ba8df5

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 10:17:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Amonetize.8
889

Agnitum Outpost
PUA.Amonetize
7.1.1

AhnLab V3 Security
PUP/Win32.Amonetize
2014.07.09

Avira AntiVirus
APPL/Bundler.Amonetize.8.12
7.11.159.122

avast!
Win32:Amonetize-CK [PUP]
2014.9-140829

AVG
Generic
2015.0.3367

Baidu Antivirus
Adware.Win32.Amonetize
4.0.3.14829

Bitdefender
Gen:Variant.Application.Bundler.Amonetize.8
1.0.20.1205

Clam AntiVirus
Win.Trojan.Hacktool-1737
0.98/21411

Dr.Web
Adware.Downware.5546
9.0.1.0241

ESET NOD32
Win32/Amonetize.BF.gen (variant)
8.10068

Fortinet FortiGate
Adware/Amonetize
8/29/2014

F-Secure
Gen:Variant.Application.Bundler
11.2014-29-08_6

G Data
Gen:Variant.Application.Bundler.Amonetize
14.8.24

K7 AntiVirus
Trojan
13.180.12657

Kaspersky
not-a-virus:AdWare.Win32.Amonetize
14.0.0.3332

Malwarebytes
PUP.Optional.Amonetize
v2014.08.29.01

McAfee
Artemis!C135824868EF
5600.7023

MicroWorld eScan
Gen:Variant.Application.Bundler.Amonetize.8
15.0.0.723

NANO AntiVirus
Riskware.Win32.Amonetize.dbyopz
0.28.0.60698

Panda Antivirus
Trj/CI.A
14.08.29.01

Sophos
Generic PUA PN
4.98

Trend Micro House Call
TROJ_GEN.R047H07G714
7.2.241

VIPRE Antivirus
Trojan.Win32.Generic
31112

Zillya! Antivirus
Trojan.Chifrax.Win32.4007
2.0.0.1851

File size:
425.1 KB (435,292 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Self-extracting archive

Common path:
C:\Program Files\windows 8.1 product key finder ultimate v14.04.1\setup.exe

File PE Metadata
Compilation timestamp:
4/29/2013 12:32:55 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:rXH38FA7I8CfAWdBqHhE3zHsy+k/bqIE6A:zHMeqfASqHhE3Qxkzql

Entry address:
0x1CC88

Entry point:
E8, 99, 58, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 35, 24, 00, 00, C7, 06, 94, 71, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, 94, 71, 42, 00, E9, EA, 24, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 94, 71, 42, 00, E8, D7, 24, 00, 00, F6, 45, 08, 01, 74, 07, 56, E8, 80, CD, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Entropy:
7.5862

Code size:
147 KB (150,528 bytes)

Remove setup.exe - Powered by Reason Core Security