Setup.exe

STart pLaying

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file Setup.exe by STart pLaying has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
XWGJS  (signed by STart pLaying)

Product:
XWGJS

Version:
6007.15530.803.4054

MD5:
db20b0a36546a527f8bbe5e3eba9703a

SHA-1:
e995e019bf3f770c64e8fbf9d0dc775bc34db9d7

SHA-256:
d9b5f9baad6fb4d31eea15618c5a95bfdf716209a8ed305fca7930ba70ec0d07

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
8/3/2025 5:47:31 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.06.15

AVG
Downloader
2016.0.3078

Dr.Web
Trojan.OutBrowse.739
9.0.1.05190

ESET NOD32
Win32/OutBrowse.CE potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
6/14/2015

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.9.5.0

K7 AntiVirus
Unwanted-Program
13.205.16237

McAfee
Program.Adware-OutBrowse.g
17.6.569.0

Quick Heal
PUA.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Outbrowse.Bundler
15.6.14.18

Trend Micro House Call
Suspici.EAD97A79
7.2.165

VIPRE Antivirus
Threat.4150696
40828

File size:
744.3 KB (762,192 bytes)

Product version:
6007.15530.803.4054

Copyright:
XWGJS

Trademarks:
XWGJS

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/27/2015 5:00:00 PM

Valid to:
12/11/2015 3:59:59 PM

Subject:
CN=STart pLaying, O=STart pLaying, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2447D23F86DE57428433972F0A8394A5

File PE Metadata
Compilation timestamp:
12/5/2009 2:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:W2dR6sypBfoOE3DhFz8+4hNRrTOF3A7n8vBiqK2McpOaZzNTDSu1pMoF0o2fc8v9:W2DvygRDhFwP/e3QnZqKJqZRH/k4j86c

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9841

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security