Setup.exe

InstallShield

Waves Inc

The program is a setup application that uses the InstallShield Setup installer. This is the uninstaller utility registered in the Windows Control Panel for the program Waves Complete V9r14 by Waves. The file has been seen being downloaded from woli.waves.com.
Publisher:
Acresso Software Inc.  (signed by Waves Inc)

Product:
InstallShield

Description:
Setup.exe

Version:
15.0.498

MD5:
c6ef1bba2cba40a756a60e697fabac9f

SHA-1:
8c55a50082268910fac69c7d557485bd69b18834

SHA-256:
c1cb9b311c0dc1440d9f85bde040d70d505a92edd9fb7f3ba7797efb27738aa6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/3/2024 9:34:04 AM UTC  (today)

File size:
388.8 KB (398,152 bytes)

Product version:
15.0

Copyright:
Copyright (C) 2008 Acresso Software Inc. and/or InstallShield Co. Inc. All Rights Reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
InstallShield Setup

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/6/2013 4:00:00 PM

Valid to:
3/7/2015 3:59:59 PM

Subject:
CN=Waves Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Waves Inc, L=Knoxville, S=Tennessee, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
279DDF11E4E4B6A99701AF0B89F2B0A4

File PE Metadata
Compilation timestamp:
5/9/2008 8:39:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:VGWK9s2n1sDEo7SUknwoD6AaeICSj7kEoed0PFn0wccccccccn:V9ysTOnKt7oUC

Entry address:
0x21EE4

Entry point:
55, 8B, EC, 6A, FF, 68, F0, A2, 44, 00, 68, 60, 49, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, FC, 92, 44, 00, 33, D2, 8A, D4, 89, 15, D0, 8B, 45, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, CC, 8B, 45, 00, C1, E1, 08, 03, CA, 89, 0D, C8, 8B, 45, 00, C1, E8, 10, A3, C4, 8B, 45, 00, 6A, 01, E8, A4, 17, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 98, 14, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.3641

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
288 KB (294,912 bytes)

Program Uninstaller
Program name:
Waves Complete V9r14

Display publisher:
Waves

Display version:
9.1.14

Uninstall string:
"C:\Program Files (x86)\InstallShield Installation Information\{91000001-C561-4E32-99EB-3C5AD3683A70}\setup.exe" -runfromtemp -l0x0009 -removeonly


The file Setup.exe has been seen being distributed by the following URL.

Scan Setup.exe - Powered by Reason Core Security