setupnt.exe

maintaining that

Sergiy Maratov

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application setupnt.exe by Sergiy Maratov has been detected as adware by 39 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex installer. It is built using the Crossrider cross-browser extension platform. While the file utilizes the Crossrider framework and delivery services, it is not owned by Crossrider.
Publisher:
databases  (signed by Sergiy Maratov)

Product:
maintaining that

Version:
0.5.0.0

MD5:
717d1dcfe1d0b1d8402677fffcdfadd2

SHA-1:
f26bfda7611d7ac80283e9589d821a24d0deebd7

SHA-256:
560b1dca2c486d842a3c7cb286e1290e19a683cc3460b9c48b33e932693a6b55

Scanner detections:
39 / 68

Status:
Adware

Explanation:
The software may change the browser's home page and search provider settings as well as display advertisements.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 6:47:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Sality.3
926

Agnitum Outpost
Win32.Sality.BL
7.1.1

AhnLab V3 Security
Win32/Kashu.E
2014.07.08

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Win32:Sality
2014.9-140723

AVG
Win32/Sality
2015.0.3404

Baidu Antivirus
Virus.Win32.Sality.$Emu
4.0.3.14723

Bitdefender
Win32.Sality.3
1.0.20.1020

Bkav FE
W32.Sality.PE
1.3.0.4959

Comodo Security
Virus.Win32.Sality.Gen
18804

Dr.Web
Trojan.Crossrider.25338
9.0.1.0204

Emsisoft Anti-Malware
Win32.Sality
8.14.07.23.03

ESET NOD32
Win32/Sality.NBA virus
8.7.0.302.0

F-Prot
W32/Sality.gen2
v6.4.6.5.141

F-Secure
Win32.Sality.3
11.2014-23-07_4

G Data
Win32.Sality
14.7.24

IKARUS anti.virus
PUP.InstallRex
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.180.12643

Kaspersky
Virus.Win32.Sality
14.0.0.3517

Malwarebytes
PUP.Optional.MultiPlug.A
v2014.07.23.03

McAfee
W32/Sality.gen.z
5600.7060

Microsoft Security Essentials
Threat.Undefined
1.177.1852.0

MicroWorld eScan
Win32.Sality.3
15.0.0.612

NANO AntiVirus
Virus.Win32.Sality.beygb
0.28.0.60698

Norman
Sality.ZHB
11.20140723

nProtect
Virus/W32.Sality.D
14.07.07.01

Panda Antivirus
W32/Sality.AA
14.07.23.03

Qihoo 360 Security
Malware.QVM19.Gen
1.0.0.1015

Quick Heal
W32.Sality.U
7.14.14.00

Reason Heuristics
PUP.Installer.SergiyMaratov.H
14.7.27.13

Rising Antivirus
PE:Win32.KUKU.kt!1591113
23.00.65.14721

Sophos
Mal/Sality-D
4.98

Total Defense
Win32/Sality.AA
37.0.11046

Trend Micro House Call
PE_SALITY.RL
7.2.204

Trend Micro
PE_SALITY.RL
10.465.23

Vba32 AntiVirus
Virus.Win32.Sality.bakc
3.12.26.3

VIPRE Antivirus
Threat.4721115
29708

ViRobot
Win32.Sality.N
2011.4.7.4223

Zillya! Antivirus
Virus.Sality.Win32.20
2.0.0.1850

File size:
1.9 MB (1,995,816 bytes)

Product version:
0.5.0.0

Copyright:
Copyright (c) 2014

Original file name:
and often Retrieval hoc

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Language:
English (United Kingdom)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\temp\setupnt.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
6/24/2014 4:43:54 AM

Valid to:
6/24/2015 4:43:54 AM

Subject:
E=SergiyIvanovich@hotmail.com, CN=Sergiy Maratov, O=Sergiy Maratov, C=RU

Issuer:
CN=Certum Code Signing CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
774A5B60838D600A3706CAB0BC5A6286

File PE Metadata
Compilation timestamp:
7/12/2014 11:12:37 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:zH22Hv0eQDFmYAzAQB8C4sS4fWQvo2xvEXwN7:zj0nDFKHB80JfWl2ZEXC

Entry address:
0x1860B

Entry point:
E8, 87, 7C, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 50, DE, 42, 00, E8, 6F, 0D, 00, 00, E8, A2, 03, 00, 00, 0F, B7, F0, 6A, 02, E8, 1A, 7C, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, C3, 45, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.9088  (probably packed)

Code size:
139.5 KB (142,848 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to r1.stylezip.info  (54.186.255.26:80)

TCP (HTTP):
Connects to c1.stylezip.info  (54.186.255.26:80)

 
http://c1.stylezip.info/?step_id=1&installer_id=8106140&publisher_id=106&source_id=0&page_id=0&country_code=US&locale=US&browser_id=4&download_id=24318420&external_id=0&session_id=48636840&hardware_id=56742980&installer_file_name=setupnt

Remove setupnt.exe - Powered by Reason Core Security