Setup.exe

MalwareBytes

Install Helper

The application Setup.exe has been detected as a potentially unwanted program by 7 anti-malware scanners. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from 1.track234e6.com.
Publisher:
Install Helper

Product:
MalwareBytes

Version:
3.0.0.104

MD5:
2960ced7562be143e9ded23e778c2b04

SHA-1:
92b0ab140914d71a0c06e4c4aedb5ff7cf3b0e38

SHA-256:
39a80d3b559c175f53786a3de3f16259f53fed9fad5a66e7b81a25ce6ffb6cc1

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Analysis date:
4/16/2024 4:54:24 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.5
5750569

Clam AntiVirus
Win.Trojan.Downloader-67726
0.98/21025

Dr.Web
Trojan.Vittalia.194
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
10.0.0.5366

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.15.21

Norman
Gen:Variant.Application.Bundler.AirInstaller.5
28.10.2015 12:55:53

File size:
876.1 KB (897,176 bytes)

Product version:
3.0.0.104

Copyright:
(c) Install Helper

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\setup.exe

File PE Metadata
Compilation timestamp:
5/30/2015 10:50:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:pvEf7yG1e3aVJtWEBSH7dpFB0FXF9o7QW:1EfvyaVJ+dYo7QW

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 10, 49, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0131

Developed / compiled with:
Microsoft Visual C++

Code size:
574 KB (587,776 bytes)

The file Setup.exe has been seen being distributed by the following URL.

Remove Setup.exe - Powered by Reason Core Security