setup.exe

SaFe SoftwaRe sLL

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by SaFe SoftwaRe sLL has been detected as adware by 30 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:
SaFe SoftwaRe sLL  (signed and verified)

MD5:
a7b70e8a75703c04423731c0cc9b96a9

SHA-1:
f9b25322b41dc69e829cd7289070229dd598be5f

SHA-256:
a3b0693c6c6c2b9459c5e0badedd183c9b7cf35c82eaeffc5a53b320c819df27

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/18/2024 9:50:51 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Adware.Generic.1228589
647

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.04.29

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
PUP-gen [PUP]
2014.9-150428

AVG
Potentially harmful program Downloader
2016.0.3125

Bitdefender
Dropped:Adware.Generic.1228589
1.0.20.590

Comodo Security
Application.Win32.AltBrowse.HY
21926

Dr.Web
Trojan.OutBrowse.326
9.0.1.0118

Emsisoft Anti-Malware
Dropped:Adware.Generic.1228589
8.15.04.28.02

ESET NOD32
Win32/OutBrowse.BU potentially unwanted
9.11545

Fortinet FortiGate
Riskware/OutBrowse
4/28/2015

F-Prot
W32/OutBrowse.N (exact, not disinfectable)
v6.4.6.5.141

F-Secure
Dropped:Adware.Generic.1228589
11.2015-28-04_3

G Data
Dropped:Adware.Generic.1228589
15.4.25

herdProtect (fuzzy)
2015.7.28.17

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.203.15734

Kaspersky
not-a-virus:AdWare.Win32.OutBrowse
14.0.0.2122

McAfee
Program.Adware-OutBrowse.e
5600.6781

MicroWorld eScan
Dropped:Adware.Generic.1228589
16.0.0.354

NANO AntiVirus
Trojan.Win32.OutBrowse.dqucfx
0.30.24.1357

nProtect
Dropped:Adware.Generic.1228589
15.04.28.01

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Reason Heuristics
Threat.Outbrowse.Bundler
15.4.28.10

Sophos
PUA 'OutBrowse Revenyou'
5.13

Trend Micro House Call
TROJ_GE.C001A90B
7.2.118

Trend Micro
TROJ_GE.C001A90B
10.465.28

Vba32 AntiVirus
Signed-Adware.Outbrowse
3.12.26.3

VIPRE Antivirus
Threat.4784459
39486

File size:
558.6 KB (571,960 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/5/2015 1:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=SaFe SoftwaRe sLL, O=SaFe SoftwaRe sLL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
48BED2CF9FCBEF623FB88AA3FDFAD281

File PE Metadata
Compilation timestamp:
12/5/2009 10:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ODFlM8TlVgq5ZhynjPSvFiUCfRwc/+QpyNNlV8P0Qa:ODFlMIl+4h+gFiUq9pyNW8v

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9637

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup.exe - Powered by Reason Core Security