setup.exe

IT River

The application setup.exe by IT River has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
IT River  (signed and verified)

Description:
Setup/Uninstall

Version:
51.52.0.0

MD5:
2f46a9b8713e93415d0dceafe916e20f

SHA-1:
e0bee2ebe8981cd325de74f9016721fb0cb4405e

SHA-256:
16df8efe0072aa39388285060a7e373f116231587dc90d027160ae995822922e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 7:46:55 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ITRiver.Installer
17.2.24.15

File size:
472.4 KB (483,688 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/25/2014 4:00:00 AM

Valid to:
2/26/2015 3:59:59 AM

Subject:
CN=IT River, O=IT River, STREET="Obolenskiy, 9", L=Moscow, S=Moscow oblast, PostalCode=119021, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0F02E0C593A3B9A15B22F5853C90D66B

File PE Metadata
Compilation timestamp:
6/20/1992 2:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x13C0

Entry point:
83, 3D, 47, 90, 46, 00, 03, 75, 31, 8B, 0D, 47, 90, 46, 00, 89, 15, 92, 90, 46, 00, 89, 1D, D6, 90, 46, 00, 87, 05, 50, 90, 46, 00, 83, 3D, DC, 90, 46, 00, 00, 75, 04, 89, C3, EB, 0C, 89, 05, 68, 90, 46, 00, 89, 1D, 4D, 90, 46, 00, 0F, 85, 14, 00, 00, 00, 4B, 87, 0D, D9, 90, 46, 00, C7, 05, BC, 90, 46, 00, 0E, 7B, 01, 00, C3, 8B, C0, 68, A0, 10, 40, 00, 21, FA, 89, 0D, 10, 90, 46, 00, 89, 05, 4B, 90, 46, 00, 89, 3D, 7D, 90, 46, 00, C7, 05, 24, 90, 46, 00, 90, 11, 40, 00, B0, 01, C3, 8B, C0, 55, 8B, EC, 83...
 
[+]

Code size:
415 KB (424,960 bytes)

Remove setup.exe - Powered by Reason Core Security