Setup.exe

ToolWiz Care

XII CNC Inc.

This is a self-extracting archive and installer. This is the uninstaller utility registered in the Windows Control Panel for the program Toolwiz Care by ToolWiz Care. This file is installed with the program Toolwiz Care.
Publisher:
ToolWiz  (signed by XII CNC Inc.)

Product:
ToolWiz Care

Version:
3.1.0.4000

MD5:
cc8942ed427c032b30eb603fc8400933

SHA-1:
f634bdcea842070569c7e62d37f273dc3c02fa7a

SHA-256:
a9116f569790ca4a4cf38e1d0e5571eeebad8f53e8275b42bdb8b8aa707439b2

Scanner detections:
5 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
12/3/2016 6:16:03 PM UTC  (ten months ago)

Scan engine
Detection
Engine version

Antiy Labs AVL
Trojan[Downloader]/Win32.Ieser
1.0.0.1

Comodo Security
UnclassifiedMalware
21349

McAfee
Artemis!CC8942ED427C
5600.6818

McAfee Web Gateway
Artemis!Trojan
7.6818

Rising Antivirus
PE:Trojan.Agent!6.670
23.00.65.15321

File size:
7.3 MB (7,634,704 bytes)

Product version:
2.0

Copyright:
Copyright(c) 2013 by ToolWiz.com

Trademarks:
ToolWiz

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/10/2013 3:00:00 AM

Valid to:
11/10/2014 2:59:59 AM

Subject:
CN=XII CNC Inc., OU=R&D Team, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=XII CNC Inc., L=Anyang-si, S=Gyeonggi-do, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0EA8B60149BC1FE40C91216292149AA7

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:kB3Q4qDjuz39uSblEFyz8Pu8z3jguh8nEwDEdhH:0Azm39uSJEFVvjUENhH

Entry address:
0xFE2001

Entry point:
60, E9, 3D, 04, 00, 00, 69, A5, 85, 81, 81, 6A, 81, 3A, B1, B8, C5, 81, 82, 5C, AA, 1C, 51, BE, C5, 81, 02, 3C, 7D, C8, C5, 81, 81, 08, 1C, 7D, C8, C5, 81, 8E, 04, E7, 82, 81, 81, 46, 04, B2, B8, C5, 81, 81, 81, 81, 81, 0C, 04, 85, CB, C5, 81, D1, 7E, 14, 81, CA, C5, 81, 08, 04, 81, CB, C5, 81, 0A, 79, 0C, 1C, 90, CB, C5, 81, D2, D1, 7E, 14, 7D, CB, C5, 81, 08, 04, 7D, BE, C5, 81, 0C, 1C, 9F, CB, C5, 81, D2, D6, 7E, 14, 7D, CB, C5, 81, 08, 04, 81, C1, C5, 81, 0C, 04, 34, B8, C5, 81, 7E, 61, 75, E8, 94, 81...
 
[+]

Packer / compiler:
ASPack v2.11

Code size:
1.3 MB (1,400,832 bytes)

Program Uninstaller
Program name:
Toolwiz Care

Display publisher:
ToolWiz Care

Display version:
3.1.0.4000

Uninstall string:
"C:\Program Files\ToolwizCareFree\UninstallToolwizCare.exe" /REMOVE


The file Setup.exe has been discovered within the following program.

Toolwiz Care  by ToolWiz
Publisher's description - “ToolWiz Care is a set of free-of-charge tools designed to speed up your PC and give your system a full range of care.”
www.Toolwiz.com
4% remove it
 
Powered by Should I Remove It?

Scan Setup.exe - Powered by Reason Core Security