setup.exe

LTD SEVEN TRANS GROUP

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by LTD SEVEN TRANS GROUP has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer.
Publisher:
LTD SEVEN TRANS GROUP  (signed and verified)

MD5:
738c05eafe7de276a9bab9ad8f9b1a6a

SHA-1:
88c8eac626ab8a524faf5592f214107bf76f14e2

SHA-256:
0fc0b0d21a88c3eddda24142ca48969305cc24fa57a15922a0199b71f0e63b6c

Scanner detections:
10 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/16/2024 5:40:43 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/Bundlore.Gen
7.11.214.34

avast!
Win32:Malware-gen
150303-0

AVG
Generic
2016.0.3179

ESET NOD32
Win32/Bundlore.S potentially unwanted application
7.0.302.0

K7 AntiVirus
Unwanted-Program
13.200.15176

Norman
InstallMonstr.CERT
11.20150306

Reason Heuristics
PUP.Bundler.Bundlore
15.3.6.0

Sophos
PUA 'Bundlore'
5.11

VIPRE Antivirus
Threat.4150696
38050

File size:
284.5 KB (291,376 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/22/2015 7:00:00 PM

Valid to:
2/23/2016 6:59:59 PM

Subject:
CN=LTD SEVEN TRANS GROUP, O=LTD SEVEN TRANS GROUP, STREET="VIDRADNYJ avenue, 95С, office 310", L=Kyiv, S=Kyivskaya, PostalCode=03061, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
68DF49B9481F1982C30D5C91387AA7AF

File PE Metadata
Compilation timestamp:
2/23/2015 10:40:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:k3uUvmeuOfq7I8ihT2pqQ4AY786/3AwJ2gdeJxJxtYd6F62/GN6Sok21JQImQVUV:Au+u2QN4AY7V3Qqc609STJ9QVUAV5Ddg

Entry address:
0x2FCA

Entry point:
E8, 0D, 48, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 28, AD, 41, 00, E8, 70, 2D, 00, 00, E8, DE, 49, 00, 00, 0F, B7, F0, 6A, 02, E8, A0, 47, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 5F, 3F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.0035

Code size:
77 KB (78,848 bytes)

Remove setup.exe - Powered by Reason Core Security