setupxv.exe

7-Zip

Igor Pavlov

The application setupxv.exe has been detected as a potentially unwanted program by 32 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.antispyware.com.
Publisher:
Igor Pavlov

Product:
7-Zip

Description:
7z Setup SFX

Version:
4.57

MD5:
a16eae5d4d8fb7ae03f58f731a912d5e

SHA-1:
03d59c618ac18d11d0ae8c29146bc6fd5929041d

SHA-256:
8d249de1765f9328dfdca87dc5af4d053d842fcb9c1212cb12ef862d8a7d6612

Scanner detections:
32 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 11:19:36 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
FraudTool.AntiSpyWare2011
7.1.1

AhnLab V3 Security
Win-Adware/Rogue.AntiSpyware.5252860
2012.12.17

Avira AntiVirus
ADSPY/AdSpy.Gen2
7.11.54.10

avast!
Win32:Dropper-gen [Drp]
2014.9-140118

AVG
SecurityTool.L
2015.0.3590

Bitdefender
Application.SpywareShield.B
1.0.20.90

Comodo Security
UnclassifiedMalware
14567

Dr.Web
Trojan.FakeAV.10454
9.0.1.018

Emsisoft Anti-Malware
Application.SpywareShield
8.14.01.18.09

ESET NOD32
Win32/Adware.SpywareRemover (variant)
8.7806

Fortinet FortiGate
W32/Malware_fam.NB
1/18/2014

F-Prot
W32/Malware!a01e
v6.4.6.5.141

F-Secure
Rogue:W32/WinFixer.AM
11.2014-18-01_7

G Data
Application.SpywareShield
14.1.22

IKARUS anti.virus
Trojan.Win32.FakeAV
t3scan.1.1.122.0

K7 AntiVirus
Riskware
13.155.7995

Kaspersky
Trojan-FakeAV.Win32.AntiSpyWare2011
14.0.0.4446

Malwarebytes
Rogue.Dropper
v2014.01.18.09

McAfee
Artemis!A16EAE5D4D8F
5600.7246

MicroWorld eScan
Application.SpywareShield.B
15.0.0.54

NANO AntiVirus
Riskware.Win32.AntiSpyWare2011.mqcyk
0.20.4.48163

Norman
W32/Suspicious_Gen2.QJULR
11.20140118

Panda Antivirus
Application/AntiSpyware2010
14.01.18.09

Quick Heal
Worm.AntiSpyWare2011.a
1.14.12.00

Rising Antivirus
Trojan.Win32.Generic.127B662C
23.00.65.14116

Sophos
Troj/FakeAV-EWA
4.84

Trend Micro House Call
TROJ_GEN.R01B4DB
7.2.18

Trend Micro
ADW_SCANNER
10.465.18

Vba32 AntiVirus
TrojanFakeAV.AntiSpyWare2011.a
3.12.18.4

VIPRE Antivirus
Trojan.Win32.Generic
14514

ViRobot
Spyware.AntiSpyWare2011.5252860
2011.4.7.4223

XVirus List
Win.Detected
2.3.31

File size:
5 MB (5,252,860 bytes)

Product version:
4.57

Copyright:
Copyright (c) 1999-2007 Igor Pavlov

Original file name:
7zS.sfx.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setupxv.exe

File PE Metadata
Compilation timestamp:
12/6/2007 11:39:15 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:tRSPDIJOw4seJjGPO+1929K4UVORCOY0lk9qM+L1ep4A2H8P8QtClTYmw:tRyDLwvsSPvL29K4UVdOhdNpeev1M7

Entry address:
0x10FC6

Entry point:
55, 8B, EC, 6A, FF, 68, D8, 38, 41, 00, 68, C0, 0F, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, EC, 30, 41, 00, 59, 83, 0D, 44, 98, 41, 00, FF, 83, 0D, 48, 98, 41, 00, FF, FF, 15, F0, 30, 41, 00, 8B, 0D, 24, 78, 41, 00, 89, 08, FF, 15, F4, 30, 41, 00, 8B, 0D, 20, 78, 41, 00, 89, 08, A1, F8, 30, 41, 00, 8B, 00, A3, 40, 98, 41, 00, E8, 19, 01, 00, 00, 39, 1D, 50, 76, 41, 00, 75, 0C, 68, 73, 37, 40, 00, FF, 15, FC, 30...
 
[+]

Entropy:
7.9958

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
70.5 KB (72,192 bytes)

The file setupxv.exe has been seen being distributed by the following URL.

Remove setupxv.exe - Powered by Reason Core Security