setup.exe

Pavel KRASNOV

This installer (utilizes the InstalleRex from WebPick) is designed to bundle additional software offerings such as adware and malware, mostly web browser extensions in the download manager, with minimal user consent. In most cases the setup process will install a browser extension for IE, Chrome and Firefox by default. The application setup.exe by Pavel KRASNOV has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex installer. The setup program uses Web-Pick's InstalleRex download manager and installer to bundle potentially unwanted ad-supported software which includes toolbars and browser extensions through a pay-per-install monetization scheme.
Publisher:
Pavel KRASNOV  (signed and verified)

MD5:
b7bfd33fbc3930c4522761cf8acec939

SHA-1:
72c10548243917ee6a6e46c8bd054c56d91bd05a

SHA-256:
9b55e3bfefb94eccdcf497d5566cd33dafea0086d41c7b3a32a998ed0857fb74

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Bundles additional adware offers in the installer/setup process.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/25/2024 11:14:43 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Dropper.101
6561816

Agnitum Outpost
PUA.MultiPlug
7.1.1

Avira AntiVirus
ADWARE/MultiPlug.Gen7
7.11.212.236

avast!
Win32:InstalleRex-AT [PUP]
150101-1

AVG
Adware Generic5.AOJB
2014.0.4253

Bitdefender
Gen:Variant.Adware.Dropper.101
1.0.20.290

Clam AntiVirus
Win.Adware.Agent-6750
0.98/20124

Comodo Security
Application.Win32.Multiplug.GETF
21235

Dr.Web
Trojan.Crossrider.4243
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Dropper.101
9.0.0.4799

ESET NOD32
Win32/AdWare.MultiPlug.R application
7.0.302.0

F-Prot
W32/S-55467851
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Dropper.101
5.13.68

G Data
Gen:Variant.Adware.Dropper.101
15.2.25

IKARUS anti.virus
AdWare.Win32.Dropper
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.1915113

Kaspersky
not-a-virus:HEUR:AdWare.Win32.Agent
14.0.0.2420

Malwarebytes
PUP.Optional.MultiPlug.A
v2015.02.27.11

McAfee
Program.PUP-FIC
16.8.708.2

MicroWorld eScan
Gen:Variant.Adware.Dropper.101
16.0.0.174

NANO AntiVirus
Trojan.Win32.Crossrider.cvwxuw
0.30.0.296

Norman
Gen:Variant.Adware.Dropper.101
03.12.2014 13:20:04

Panda Antivirus
Trj/Genetic.gen
15.02.27.11

Quick Heal
AdWare.MultiPlag.ace
2.15.14.00

Reason Heuristics
PUP.Installer.WebPick
15.2.27.23

Rising Antivirus
PE:AdWare.Win32.MultiPlug.n!1075356180
23.00.65.15225

Sophos
PUA 'MultiPlug' (of type Adware)
5.11

Vba32 AntiVirus
BScope.Adware.MegaSearch
3.12.26.3

VIPRE Antivirus
Threat.4786450
37788

Zillya! Antivirus
Trojan.Black.Win32.17053
2.0.0.2084

File size:
1.5 MB (1,564,792 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\windows\syswow64\setup.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
1/17/2014 2:46:29 AM

Valid to:
1/17/2015 2:46:29 AM

Subject:
E=pavel0125@hotmail.com, CN="Open Source Developer, Pavel KRASNOV", O=Pavel KRASNOV, C=RU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
145B82E22CCF1D1A2268198D76B51075

File PE Metadata
Compilation timestamp:
2/18/2014 3:40:34 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:BpTZMuc9Nho0aTuptDWYSmlf736nKaRnhOiZXPB/R8Ie9pwqK7UhdG9PmqLbjADb:7Zm9To0qAgYlrMhXblezwjUhdG93b2b

Entry address:
0x107CB

Entry point:
E8, 7E, 49, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 20, 11, 42, 00, E8, 5F, 20, 00, 00, E8, E0, 07, 00, 00, 0F, B7, F0, 6A, 02, E8, 11, 49, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, D0, 36, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.9168  (probably packed)

Code size:
97 KB (99,328 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i1.stylefun.info  (198.7.61.118:80)

TCP (HTTP):
Connects to dl.softservers.net  (184.154.145.171:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

Remove setup.exe - Powered by Reason Core Security