setup_2997.exe

SoftwareSetup

Guangxi Nanning Shengtaian E-commerce Development Co., Ltd.

The application setup_2997.exe by Guangxi Nanning Shengtaian E-commerce Development Co. has been detected as a potentially unwanted program by 13 anti-malware scanners. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent.
Publisher:
Sta  (signed by Guangxi Nanning Shengtaian E-commerce Development Co., Ltd.)

Product:
SoftwareSetup

Version:
1.0.0.1

MD5:
0ffda624c26e3016ab3a301b95d03413

SHA-1:
3b69b6568724d95a72e1d620abec87baea37a738

SHA-256:
772447a79eba10b77b510cc08b6bc01b137a86430e0eefa80cc22ea48f064258

Scanner detections:
13 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
4/18/2024 5:34:50 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W32.Clod099.Trojan
1.3.0.4959

Comodo Security
UnclassifiedMalware
17893

Dr.Web
Trojan.Inject1.29920
9.0.1.083

ESET NOD32
probably unknown NewHeur_PE
8.9509

IKARUS anti.virus
AdWare.Downloader
t3scan.2.2.29

K7 AntiVirus
Trojan
13.176.11367

Malwarebytes
PUP.Optional.BundleInstaller.A
v2014.03.24.11

McAfee
Artemis!0FFDA624C26E
5600.7181

NANO AntiVirus
Trojan.Win32.Inject1.crapwy
0.28.0.58101

Norman
Downloader
11.20140324

Rising Antivirus
PE:Trojan.Win32.Generic.16093374!369701748
23.00.65.14322

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.24.3

XVirus List
Win.Detected
2.3.31

File size:
56.8 KB (58,168 bytes)

Product version:
1.0.0.1

Copyright:
Copyright (C) 2013

Original file name:
DownSoft.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup_2997.exe

Digital Signature
Authority:
WoSign eCommerce Services Limited

Valid from:
6/2/2013 10:58:04 PM

Valid to:
7/6/2014 9:14:35 AM

Subject:
E=kefu@shengtaian.com, CN="Guangxi Nanning Shengtaian E-commerce Development Co., Ltd.", O="Guangxi Nanning Shengtaian E-commerce Development Co., Ltd.", L=Nanning, S=Guangxi Zhuangzu Zizhiqu, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA, O=WoSign eCommerce Services Limited, C=CN

Serial number:
039E5E3EE7A9AB

File PE Metadata
Compilation timestamp:
7/16/2013 11:42:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:K9Maz1kop7Yy4hb+Yin2CEDvcjU9tOmv96vao6DYLvfJzSpL0GFK:KSu1koJgb+L92gYwuwvh7GI

Entry address:
0x1B6A

Entry point:
E8, 00, 27, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 58, AC, 40, 00, 89, 0D, 54, AC, 40, 00, 89, 15, 50, AC, 40, 00, 89, 1D, 4C, AC, 40, 00, 89, 35, 48, AC, 40, 00, 89, 3D, 44, AC, 40, 00, 66, 8C, 15, 70, AC, 40, 00, 66, 8C, 0D, 64, AC, 40, 00, 66, 8C, 1D, 40, AC, 40, 00, 66, 8C, 05, 3C, AC, 40, 00, 66, 8C, 25, 38, AC, 40, 00, 66, 8C, 2D, 34, AC, 40, 00, 9C, 8F, 05, 68, AC, 40, 00, 8B, 45, 00, A3, 5C, AC, 40, 00, 8B, 45, 04, A3, 60, AC, 40, 00, 8D, 45, 08, A3, 6C, AC, 40...
 
[+]

Entropy:
6.2304

Code size:
20.5 KB (20,992 bytes)

Remove setup_2997.exe - Powered by Reason Core Security