setup.exe

Iqdenwj & co.

The application setup.exe has been detected as a potentially unwanted program by 37 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars.
Publisher:
Iqdenwj & co.

Description:
Zuopzuus

Version:
4.23.4.17

MD5:
e967b9e8e02d7c8895bb55e15c2a977a

SHA-1:
8b7afbc5c9474f3deadd7dab243947cad1a4e726

SHA-256:
7082ea07911f6d8aa8f4e3e41a38678caf67a9bd1e2549105a34c1acceabd431

Scanner detections:
37 / 68

Status:
Potentially unwanted

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/19/2024 12:49:39 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Solimba.1
801

Agnitum Outpost
Trojan.Adware
7.1.1

AhnLab V3 Security
ASD.Prevention
2013.06.28

Avira AntiVirus
APPL/Solimba.Gen
7.11.61.98

avast!
Win32:PUP-gen [PUP]
2014.9-141126

AVG
AdInstaller.Q
2015.0.3279

Baidu Antivirus
Trojan.MSIL.Solimba
4.0.3.141126

Bitdefender
Gen:Variant.Adware.Solimba.1
1.0.20.1650

Clam AntiVirus
WIN.Adware.Solimba-3
0.98/18355

Comodo Security
Application.Win32.Solimba.a
15261

Dr.Web
Adware.Downware.798
9.0.1.0330

Emsisoft Anti-Malware
Gen:Variant.Adware.Solimba
8.14.11.26.04

ESET NOD32
MSIL/Solimba
8.8016

Fortinet FortiGate
Adware/Fam.NB
11/26/2014

F-Prot
W32/Solimba.B.gen
v6.4.6.5.141

F-Secure
Gen:Variant.Adware.Solimba.1
11.2014-26-11_4

G Data
Gen:Variant.Adware.Solimba
14.11.22

IKARUS anti.virus
AdWare.Solimba
t3scan.2.0.3.0

K7 AntiVirus
Unwanted-Program
13.160.8223

Kaspersky
not-a-virus:AdWare.MSIL.Solimba
14.0.0.2889

Malwarebytes
PUP.Offerware
v2014.11.26.04

McAfee
Artemis!395ECAAEE6AD
5600.6935

MicroWorld eScan
Gen:Variant.Adware.Solimba.1
15.0.0.990

NANO AntiVirus
Riskware.Win32.Downware.cruvdx
0.28.0.58101

Norman
Solimba.DIMI
11.20141126

nProtect
Trojan/W32.Agent.178856.B
13.02.15.02

Qihoo 360 Security
HEUR/Malware.QVM20.Gen
1.0.0.1015

Quick Heal
AdWare.MSIL.Solimba.c (Not a Virus)
11.14.12.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.11.26.4

Rising Antivirus
Trojan.Win32.Generic.13FD7DA9
23.00.65.141124

Sophos
DownloadMR
4.93

SUPERAntiSpyware
Trojan.Agent/Gen-Solimba
10215

Trend Micro House Call
TROJ_GEN.RCBOHLU
7.2.330

Trend Micro
TROJ_GEN.RCBCOEK
10.465.26

Vba32 AntiVirus
Downware.Morstar
3.12.24.3

VIPRE Antivirus
DownloadMR
26878

XVirus List
Win32.Detected
2.7.5

File size:
12.7 MB (13,305,408 bytes)

Copyright:
Copyright Seizrsvzmpmgj

Trademarks:
Cmvoqhbovja is a trademark of Ofvhyqpegixw

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\opencandy\dcfee16f998e48fdb0c6103d68af9930\setup.exe

File PE Metadata
Compilation timestamp:
12/4/2012 6:55:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

CTPH (ssdeep):
393216:ALTQ5g8WQKSUybxV9ETXApAALxwOhplTJ5wvw:A/Q5/f9V9iwLxp9uY

Entry address:
0x412D

Entry point:
60, 69, DF, 25, 66, 69, 06, 68, 6D, A9, 32, 00, 3D, 93, 39, 00, 00, 76, 06, C7, C0, 06, F7, 13, 54, 8D, 0D, 70, A0, 36, B1, C6, C3, EB, 74, 0F, 69, C2, A9, 9F, 5C, 7A, 0F, AF, E9, 81, CE, C4, 90, 7D, 30, 76, 05, 0F, AF, EB, FE, C1, 87, F6, 13, C5, 0F, BF, EF, 68, 36, 1A, 00, 00, 8B, FE, FF, C1, 5A, 00, F9, 81, EA, 87, 0B, 00, 00, 70, 06, 89, FB, 0F, AF, C0, 4B, F7, C3, 70, 3E, 2E, 25, 77, 07, 69, CF, E2, 17, 3E, 22, 43, 87, E9, FE, CD, 68, 23, 8D, F4, FF, 8A, F9, FE, C9, 58, EB, 05, BE, D6, 6E, CB, 21, 35...
 
[+]

Entropy:
7.9995  (probably packed)

Code size:
33.5 KB (34,304 bytes)

Remove setup.exe - Powered by Reason Core Security