setup.exe

Moozy

Conversionads

The application setup.exe, “Moozy Setup ” by Conversionads has been detected as adware by 21 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. It is also typically executed from an Internet Explorer cache folder.
Publisher:
Conversionads  (signed and verified)

Product:
Moozy

Description:
Moozy Setup

MD5:
46d88855396ce5eedf6a4dff844a043d

SHA-1:
7e9315b18640aaa5caad2a4162b3f87cab8a060b

SHA-256:
25049992a38523543cbb7b1b73ec272bda9132e4807cdb4a235ab995eae9e5cb

Scanner detections:
21 / 68

Status:
Adware

Analysis date:
4/25/2024 3:52:14 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/Agent.NMP
7.11.105.176

avast!
Win32:AddLyrics-A [Adw]
2014.9-160101

AVG
Agent.F
2017.0.2878

Comodo Security
ApplicUnwnt
17040

Dr.Web
Adware.Zugo.71
9.0.1.01

Emsisoft Anti-Malware
Virus.Win32.Heur!IK
8.16.01.01.11

ESET NOD32
Win32/Toolbar.Zugo
10.10317

Fortinet FortiGate
W32/Toolbar.ZUGO
1/1/2016

F-Prot
W32/SuspPack.D.gen
v6.4.6.5.141

F-Secure
Adware.Agent.NMP
11.2016-01-01_6

IKARUS anti.virus
Virus.Win32.Heur
t3scan.1.1.107.0

K7 AntiVirus
Riskware
13.120.5775

McAfee
Artemis!3B1832F23E25
5600.6534

MicroWorld eScan
Adware.Agent.NMP
17.0.0.3

NANO AntiVirus
Riskware.Win32.SearchAssistant.clxqh
0.26.0.55203

Reason Heuristics
PUP.Conversionads.Installer (M)
16.1.1.11

Sophos
Conversion Ads
4.93

Trend Micro House Call
ADW_ZUGO
7.2.1

Trend Micro
ADW_ZUGO
10.465.01

Vba32 AntiVirus
AdWare.SearchAssistant
3.12.24.3

VIPRE Antivirus
Trojan.Win32.Generic
11005

File size:
1.5 MB (1,625,112 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
6/5/2011 5:00:00 PM

Valid to:
6/5/2012 4:59:59 PM

Subject:
CN=Conversionads, O=Conversionads, STREET=Am Weinberg 5, L=Neubeuern, S=Neubeuern, PostalCode=83115, C=DE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00C774EE3B8DAE0D50741CD0F860CE601C

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:YexXIy+ZmN76KK02OqPqeckRIuUeLCgvhg:xb9/qPqlKU+v+

Entry address:
0x9C18

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, AE, 94, FF, FF, E8, B5, A6, FF, FF, E8, 44, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, D4, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 9D, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 5A, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9893

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove setup.exe - Powered by Reason Core Security