Setup.exe

The file Setup.exe has been detected as a potentially unwanted program by 9 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
MD5:
94d07b7e52fa982f7b07252c937c6ad6

SHA-1:
b2a85abcace6cc83992739e6fd136ca8dc86816b

SHA-256:
42acf097f79dd468d07c4513d2c24651059769be25fdb4ebfe8f63627a6efd73

Scanner detections:
9 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 12:04:12 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen
3.6.1.96

Baidu Antivirus
PUA.Win32.Addrop.InstallCore
4.0.3.15520

ESET NOD32
Win32/TrojanDropper.Addrop
9.11530

herdProtect (fuzzy)
2015.7.26.3

K7 AntiVirus
Trojan
13.203.15829

Qihoo 360 Security
HEUR/QVM42.0.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Trojan.Win32.Generic.18995950!412703056
23.00.65.15724

Sophos
Generic PUA IP
4.98

Trend Micro House Call
Suspicious_GEN.F47V0425
7.2.140

File size:
937.1 KB (959,551 bytes)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:uoL/AF11t5PqbEDUCWroUhbXwyv8x5YCZq72VKk1GP87Gre4lKl:uu/6rtFqbVoUhbXws8xiHCFh7Gy4Q

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
6.7663

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security