Setup.exe

The file Setup.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
MD5:
890e8bba9253299c4ea4906442d00173

SHA-1:
8fb90643333ad235f3f0fa14c6e261bff1f40382

SHA-256:
7211093cc60f2e33fc057fb63f37a3e0c12c3bd7d74a1c41a0e368e7e3eda36c

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 12:44:54 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
3.6.1.96

Baidu Antivirus
PUA.Win32.Addrop.InstallCore
4.0.3.15520

ESET NOD32
Win32/TrojanDropper.Addrop.C trojan
7.0.302.0

herdProtect (fuzzy)
2015.7.26.3

K7 AntiVirus
Trojan
13.203.15829

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.18995950!412703056
23.00.65.15724

Sophos
Generic PUA IP
4.98

Trend Micro House Call
Suspicious_GEN.F47V0425
7.2.140

File size:
954.8 KB (977,716 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:uoL/AF11t5PqbEDUCWroUhbXwyv8x5YCZq72VKk1GP87Gre4lKl:uu/6rtFqbVoUhbXws8xiHCFh7Gy4Q

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.6764

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security