setup.exe

Clovermedia SLU

This is the Tuguu DomaIQ download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Clovermedia SLU has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the TUGUU DomaIQ Setup installer.
Publisher:
Clovermedia SLU  (signed and verified)

MD5:
5eb503aba9dd176d678c4c10b6c00aa5

SHA-1:
cd9c6ac839875820ec0e754463529f556b67f832

SHA-256:
ed5a8ff7be3c480e2420a10026a3aa35d8390338d1fc42ec49c058dca74f80c1

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/23/2024 10:11:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.923740
1019

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
PUP/Win32.DomaIQ
14.04.21

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.144.160

AVG
DomaIQ_r.I
2015.0.3497

Comodo Security
Application.Win32.DomaIQ.PUP
18142

ESET NOD32
Win32/DomaIQ.BB (variant)
8.9703

F-Secure
Adware:W32/DomaIQ
11.2014-21-04_2

herdProtect (fuzzy)
2014.7.18.20

IKARUS anti.virus
AdWare.SuspectCRC
t3scan.1.6.1.0

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3982

Malwarebytes
PUP.Optional.DomaIQ
v2014.04.21.03

McAfee
RDN/Generic PUP.x!b2b
5600.7153

MicroWorld eScan
Adware.Generic.923740
15.0.0.333

NANO AntiVirus
Riskware.Win32.DomaIQ.cwclcv
0.28.0.59492

Panda Antivirus
Trj/Genetic.gen
14.04.21.03

Reason Heuristics
PUP.Installer.ClovermediaSLU.F
14.4.21.15

Sophos
DomainIQ pay-per install
4.98

VIPRE Antivirus
Trojan.Win32.Generic
28462

File size:
384.5 KB (393,712 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
TUGUU DomaIQ Setup

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/14/2014 2:00:00 AM

Valid to:
2/15/2015 1:59:59 AM

Subject:
CN=Clovermedia SLU, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Clovermedia SLU, L=Adeje, S=Santa Cruz de tenerife, C=ES

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0524A867F334951775CD16FBB2ED7E9B

File PE Metadata
Compilation timestamp:
4/1/2014 12:43:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:qYhA8/eZDYI2w+8RGQJ5pfyQleyteqo44TL3dVl5Cbr22ouqbYA8cYd/:qA/eZr2w+8BJ50Q0BbDNVl5Qrc8l/

Entry address:
0x3B36

Entry point:
E8, 37, 2C, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, BC, 6C, 41, 00, FF, 15, 6C, B0, 40, 00, 85, C0, 75, 18, 56, E8, 4B, 0C, 00, 00, 8B, F0, FF, 15, 50, B0, 40, 00, 50, E8, 50, 0C, 00, 00, 59, 89, 06, 5E, 5D, C3, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 7F, 0F, B6, 44, 24, 08, 0F, BA, 25, 88, 69, 41, 00, 01, 73, 0D, 8B, 4C, 24, 0C, 57, 8B, 7C, 24, 08, F3, AA, EB, 5D, 8B, 54, 24, 0C, 81, FA, 80, 00, 00, 00, 7C, 0E, 0F, BA...
 
[+]

Entropy:
6.4029

Code size:
39.5 KB (40,448 bytes)

Remove setup.exe - Powered by Reason Core Security