setup.exe

Teras Games

Today Solutions

The application setup.exe by Today Solutions has been detected as a potentially unwanted program by 20 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from cdn.airdlr.com.
Publisher:
Today Solutions  (signed and verified)

Product:
Teras Games

Version:
3.0.85.3

MD5:
992c3e0d5b373a92fa37e633b4e856b6

SHA-1:
f8f29c7a43f19825bd846d0a621d7473abf1d99d

SHA-256:
a46f55cd7cc206bc9e76e9cdf1a99b3adac89a91d0161c2aecdac6a9f99ab857

Scanner detections:
20 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 8:54:59 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1513578
393

Avira AntiVirus
ADWARE/PullUpdate.Gen7
8.3.2.4

avast!
Adware-gen [Adw]
2014.9-160107

AVG
Generic
2017.0.2871

Clam AntiVirus
Win.Trojan.Pullupdate-2
0.98/21160

Dr.Web
infected with Trojan.Yontoo.2830
9.0.1.07

ESET NOD32
MSIL/Adware.PullUpdate.J.gen application
10.7.0.302.0

F-Secure
Gen:Variant.Midie.4387
11.2016-07-01_5

IKARUS anti.virus
Trojan.Win32.SelfDel
t3scan.1.9.5.0

K7 AntiVirus
Adware
13.212.18027

Malwarebytes
PUP.Optional.TerasGames
v2016.01.07.06

McAfee
Artemis!82544BC45C02
5600.6527

MicroWorld eScan
Application.Generic.1513578
17.0.0.21

Panda Antivirus
Trj/Genetic.gen
16.01.07.06

Qihoo 360 Security
HEUR/QVM41.1.Malware.Gen
1.0.0.1077

Reason Heuristics
PUP.Injekt.TodaySolutions.Installer (M)
16.1.7.18

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.16105

Vba32 AntiVirus
Trojan.SelfDel
3.12.26.4

VIPRE Antivirus
Threat.4872425
45548

Zillya! Antivirus
Adware.PullUpdate.Win32.31366
2.0.0.2548

File size:
5.1 MB (5,399,952 bytes)

Product version:
3.0.85.3

Copyright:
Copyright (C) 2015 Today Solutions

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
9/15/2015 6:00:00 PM

Valid to:
11/9/2015 4:59:59 PM

Subject:
CN=Today Solutions, O=Today Solutions, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
59F99F88FD0FBB35EEA7B60F3F4E8CD7

File PE Metadata
Compilation timestamp:
10/5/2015 12:54:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
98304:W95hRLlbLDVUisNFVeaWBafdjtRP9yGKhsJqoc4q2hqbHdxpW1c+o9UbX:W9LRZbLDKhVenIRt+GKoBqYqb9yfo9U7

Entry address:
0x6EA7

Entry point:
E8, CF, 7D, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, F0, 35, 42, 00, E8, D3, 55, 00, 00, E8, 54, 2A, 00, 00, 0F, B7, F0, 6A, 02, E8, 62, 7D, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 74, 53, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.8207  (probably packed)

Code size:
106.5 KB (109,056 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security