Setup.exe

Creative Island Media, LLC

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application Setup.exe by Creative Island Media has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from d.websteroidsapp.com. While running, it connects to the Internet address update.betterxperience.com on port 80 using the HTTP protocol.
Publisher:
Creative Island Media, LLC  (signed and verified)

MD5:
85cc6475212ab6f13b4b9eb7327c9155

SHA-1:
cd4eba4fb847650e164b3fcd55fd60bc982693b6

SHA-256:
73b9cb4088d82274f26a46ee8436e8170085cec0dc5b47b33e2617c1f9b9e1c7

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 4:54:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Adware.Agent.NUR
1033

Agnitum Outpost
PUA.PullUpdate
7.1.1

Avira AntiVirus
Adware/Agent.nur.15
7.11.140.94

Bitdefender
Dropped:Adware.Agent.NUR
1.0.20.490

Comodo Security
ApplicUnwnt
18025

Dr.Web
Adware.Plugin.128
9.0.1.098

Emsisoft Anti-Malware
Dropped:Adware.Agent.NUR
8.14.04.08.11

ESET NOD32
MSIL/Adware.PullUpdate
8.9617

Fortinet FortiGate
Adware/PullUpdate
4/8/2014

F-Secure
Adware.Agent.NUR
11.2014-08-04_3

G Data
Dropped:Adware.Agent.NUR
14.4.24

K7 AntiVirus
Unwanted-Program
13.176.11613

Kaspersky
not-a-virus:AdWare.Win32.SaMon
14.0.0.4048

Malwarebytes
PUP.Optional.WebSteroids.A
v2014.04.08.11

McAfee
Artemis!85CC6475212A
5600.7167

MicroWorld eScan
Dropped:Adware.Agent.NUR
15.0.0.294

nProtect
Dropped:Adware.Agent.NUR
14.03.31.01

Qihoo 360 Security
Win32/Trojan.Adware.988
1.0.0.1015

Reason Heuristics
PUP.Installer.CreativeIslandMedia.F
14.8.7.20

Sophos
Search Donkey
4.98

Trend Micro House Call
TROJ_GEN.F47V0326
7.2.98

Vba32 AntiVirus
TScope.Trojan.MSIL
3.12.24.3

VIPRE Antivirus
SearchDonkey
27896

File size:
3 MB (3,165,608 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/20/2013 8:00:00 PM

Valid to:
5/21/2014 7:59:59 PM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
6/6/2009 5:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:/VV83ho42AtfMdqiOzLBJ3VwG4OwpnlrEiY8k6npM3RwRoUnZl:/Q3hBR0qiqVwtdllrEi7u3RwhnZl

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9611

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file Setup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

TCP (HTTP):
Connects to d.betterxperience.com  (54.230.13.123:80)

 
http://d.betterxperience.com/updater/dedu.txt

Remove Setup.exe - Powered by Reason Core Security