setup.exe

Rational Thought Solutions

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Rational Thought Solutions has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from e46m3.vanoshield.com.
Publisher:
Rational Thought Solutions  (signed and verified)

MD5:
1da7d7b832672112637d013888bbabe7

SHA-1:
724e42ce705e78fbb4e724ab1ff2c2a4ef8a0777

SHA-256:
c3e8975df29cf74b8b1244d5de9e431253b584b920fe794f2b4e59c6512acc64

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/30/2024 2:30:10 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen7
8.3.1.6

AVG
Generic
2016.0.3093

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.15530

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
ApplicUnwnt
22283

Dr.Web
Adware.Yontoo.68
9.0.1.05190

ESET NOD32
MSIL/Adware.PullUpdate.J.gen application
7.0.302.0

Malwarebytes
PUP.Optional.PullUpdate.A
v2015.05.30.06

NANO AntiVirus
Riskware.Nsis.Yontoo.dqgtsc
0.30.24.1636

Reason Heuristics
PUP.Injekt.Installer
15.5.30.18

File size:
4.1 MB (4,247,640 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\qcq81qt4nq\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
1/24/2015 12:00:00 AM

Valid to:
4/25/2016 12:59:59 AM

Subject:
CN=Rational Thought Solutions, O=Rational Thought Solutions, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
00B81C1C4DB6AD87B9B581116F115E4C

File PE Metadata
Compilation timestamp:
6/6/2009 10:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:6ML+WO6PhZjZVRV1Bo6IknyignZsO+LNhNkES6KgKL/kyv9c:RLTOCbZfVjonkyi7hh7S3g28yC

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9993

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security