Setup.exe

IMVU

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The file Setup.exe, “IMVU Setup ” by ClientConnect has been detected as adware by 7 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
ClientConnect LTD  (signed and verified)

Product:
IMVU

Description:
IMVU Setup

Version:
1.8.2.2

MD5:
19a04b6b7cb2d45a0a6f613b82522673

SHA-1:
e2411530e2e147126746b094684a6b93f2124da8

SHA-256:
e3bb0e6f79d7d264a37e48e63e4656acba2936fc67fa4b7fb8a67f9564add1b5

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
4/26/2024 3:31:04 AM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
PUA.Win32.ClientConnect
4.0.3.15116

Dr.Web
Adware.Conduit.179
9.0.1.0310

ESET NOD32
Win32/ClientConnect.A potentially unwanted (variant)
9.11201

Fortinet FortiGate
Riskware/ClientConnect
11/6/2015

Reason Heuristics
PUP.Conduit.ClientConnect.Installer (M)
15.11.6.9

Trend Micro House Call
Suspicious_GEN.F47V0205
7.2.310

VIPRE Antivirus
Conduit
37704

File size:
619.7 KB (634,560 bytes)

Product version:
1.8.2.2

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/3/2014 8:00:00 PM

Valid to:
2/5/2016 7:59:59 PM

Subject:
CN=ClientConnect LTD, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Prod3, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1DE981E6776F551E66C8506523102501

File PE Metadata
Compilation timestamp:
7/9/2014 4:58:13 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:/SxG0B888888888888W888888888882Q8AHNlLXR7e/+HUNKaIo3DJ4yhqJw/UpX:axG5Q8UlLh6GHUoaIo3V4SqJwsph+Fo

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.7920

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/33279699/33300822/?mainofferId=33276265&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.3.32.33299688.01&Language=US-EN

Remove Setup.exe - Powered by Reason Core Security