setup.exe

Acute Angle Solutions Ltd.

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Acute Angle Solutions has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from d.downloadmeteoroids.com.
Publisher:
Acute Angle Solutions Ltd.  (signed and verified)

MD5:
c1ca88fd9f93fc4041cf2095b243a26d

SHA-1:
c3bb10a69f27ffa4afb2debc2c8d8b9033194fcf

SHA-256:
e0f1546d762b9eaddea68b345d88f0408857b5860d85202ed9a08d97d946774b

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/29/2024 3:36:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.728095
848

Agnitum Outpost
PUA.PullUpdate
7.1.1

AVG
Acute
2015.0.3326

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.141010

Bitdefender
Application.Generic.728095
1.0.20.1415

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
multiple threats
7.0.302.0

Fortinet FortiGate
Adware/PullUpdate
10/10/2014

F-Secure
Application.Generic.728095
11.2014-10-10_6

G Data
Application.Generic.728095
14.10.24

IKARUS anti.virus
PUA.Generic
t3scan.1.7.8.0

K7 AntiVirus
Adware
13.183.13630

Malwarebytes
PUP.Optional.PullUpdate
v2014.10.10.03

McAfee
Artemis!84490CE64670
5600.6982

MicroWorld eScan
Application.Generic.728095
15.0.0.849

Reason Heuristics
PUP.Installer.AcuteAngleSolutions.F
14.10.10.3

Sophos
Pull Update
4.98

Trend Micro House Call
Suspici.63D1E3E6
7.2.283

VIPRE Antivirus
Threat.4784449
33706

File size:
3.9 MB (4,129,664 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/30/2014 4:00:00 PM

Valid to:
1/31/2015 3:59:59 PM

Subject:
CN=Acute Angle Solutions Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Acute Angle Solutions Ltd., L=St. James, S=St. James, C=BB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0A7A77148C6F7A33F9174DA187F6FEF0

File PE Metadata
Compilation timestamp:
6/6/2009 2:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:obqWKl8chYV52Bp9djrK3d/6/R5VkWKl:2xxD2pnSh6V

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9765

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security