Setup.exe

Generic

OOO Mad Advert

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The file Setup.exe, “Generic Setup ” by OOO Mad Advert has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Program   (signed by OOO Mad Advert)

Product:
Generic

Description:
Generic Setup

Version:
4.2.3.1

MD5:
d17e184b8a53f2a87fa0140891e17c7b

SHA-1:
9032a4f25ba0b1657b83eef4f43d02c7942cf44f

SHA-256:
7304f542bde366bf1287a2e123f7ba415c9d3167a26f25cdc18b2864b27f02ef

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
8/9/2025 1:50:32 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Trojan-gen
2014.9-150409

Comodo Security
Application.Win32.InstallCore.DAF
21651

ESET NOD32
Win32/InstallCore.YK potentially unwanted application
9.7.0.302.0

File size:
781.9 KB (800,704 bytes)

Product version:
1.0

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/18/2015 8:00:00 PM

Valid to:
3/18/2016 7:59:59 PM

Subject:
CN=OOO Mad Advert, O=OOO Mad Advert, STREET="Andronevskaya B., d. 7/14 str. 1 of. 1205", L=Moscow, S=Moscow, PostalCode=109544, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0080C5CB45D047D2C30BE1A2662DE771D1

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:UNspT7+ehkPePrZ3kr4B0Z7r/3BfQ6qdpRZN7MZz1566qiTiYQFG+QtQw:UNstyehket06o3VQZLRZKs6fWRFtQtQw

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.6766

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove Setup.exe - Powered by Reason Core Security