setup.exe

Bundlore Limited

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Bundlore Limited has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer.
Publisher:
Bundlore Limited  (signed and verified)

MD5:
3eadbdc328343cd10e011bafe0367fbb

SHA-1:
d718c3fe1339d262060a48108610d7d70cf2e9f9

SHA-256:
34913951984ed831815cc25c0d98e6c06a57fa6644dbec625a1669a4a925835d

Scanner detections:
22 / 68

Status:
Adware

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/18/2024 11:34:57 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.MPlug.6
856

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Bundlore
2014.10.03

Avira AntiVirus
APPL/Downloader.Gen9
7.11.176.50

AVG
Bundlo
2015.0.3334

Bitdefender
Gen:Variant.Adware.MPlug.6
1.0.20.1375

Clam AntiVirus
Win.Adware.Agent-15602
0.98/19466

Comodo Security
Application.Win32.Bundlore.L
19681

Dr.Web
Adware.Downware.8464
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.MPlug
8.14.10.02.09

ESET NOD32
Win32/Bundlore.M potentially unwanted application
7.0.302.0

F-Prot
W32/A-aeabd9bb
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.MPlug.6
11.2014-02-10_5

G Data
Gen:Variant.Adware.MPlug
14.10.24

K7 AntiVirus
Unwanted-Program
13.183.13550

McAfee
PUP-FLY
5600.6990

MicroWorld eScan
Gen:Variant.Adware.MPlug.6
15.0.0.825

NANO AntiVirus
Riskware.Win32.Downware.deufsj
0.28.2.62440

Reason Heuristics
PUP.Installer.BundloreLimited.F
14.10.2.9

Sophos
Bundlore
4.98

SUPERAntiSpyware
PUP.Bundlore
10324

VIPRE Antivirus
Threat.4150696
33520

File size:
264.4 KB (270,704 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/12/2013 2:00:00 AM

Valid to:
9/13/2014 1:59:59 AM

Subject:
CN=Bundlore Limited, O=Bundlore Limited, L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
232CE5297F2941A352148152A936FB93

File PE Metadata
Compilation timestamp:
8/6/2014 11:22:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:m799aT9djCVApiYR46agsI18Nki5cscIfK:+99a5djkAIi/7ekiPcuK

Entry address:
0x4FE3

Entry point:
E8, 56, 48, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, A8, B2, 41, 00, E8, D7, 1D, 00, 00, E8, 34, 2F, 00, 00, 0F, B7, F0, 6A, 02, E8, E9, 47, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, A8, 3F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
80 KB (81,920 bytes)

Remove setup.exe - Powered by Reason Core Security