SETUPPROCESS

Publisher Information

SETUPPROCESS is a software publisher located in Badalona, Barcelona in Spain*. The company is a primary distributor of unwanted software. SETUPPROCESS run by Firseria/Solimba Aplicaciones S.L. based on Spain is a company that runs various download portals including winportal.com which is designed as a download site that distributes legitimate software, however they use a custom download manager (DownloadMR) to package bundled offers with each installation that include adware, toolbars and various other potential unwanted software.
Remove SETUPPROCESS Malware - Powered by Reason Core Security
Authority:
DigiCert Inc

Valid from:
11/26/2013 10:00:00 PM

Valid to:
12/1/2014 10:00:00 AM

Subject:
CN=SETUPPROCESS, O=SETUPPROCESS, L=Badalona, S=Barcelona, C=ES

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0a8abfc7c80d0c2f0a3a89cf6139a91d

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Solimba.SETUPPROCESS.Bundler (M)
100.00%

Dr.Web
Trojan.DownLoader11.3531
8.00%

VIPRE Antivirus
Threat.4150696
8.00%

avast!
Win32:PUP-gen [PUP]
8.00%

ESET NOD32
Win32/FirseriaInstaller.C potentially unwanted application
8.00%

Clam AntiVirus
Win.Trojan.Morstar
8.00%

Kaspersky
not-a-virus:Downloader.Win32.Morstar
8.00%

MicroWorld eScan
Gen:Application.Bundler.Firseria.1
8.00%

CMC Antivirus
Trojan.Win32.VBKrypt!O
8.00%

Quick Heal
TrojanDownloader.Morstar.O3
8.00%

1 / 68      (Adware)
winqsb.exe (by setupprocess)  (b211e2a739fd91e5fcd3732925a22f15)

1 / 68      (Adware)
microsoft office outlook 2007.exe (by setupprocess)  (119f601fcdbfa060b1a17ed366a40c77)

1 / 68      (Adware)
cutepdf writer.exe (by setupprocess)  (7c6cfb3db93e072ac6a9e35a25c8d9aa)

1 / 68      (Adware)
pro evolution soccer 2013 (pes).exe (by setupprocess)  (0b42a2f75a56664c5614d7e3fb85fe05)

1 / 68      (Adware)
zuma deluxe.exe (by setup process)  (4b9685ab35636c62e9a7cb8fb30be9c3)

1 / 68      (Adware)
adobe reader.exe (by Rapiddown)  (783d29ea80a94dd6e5f04c09d25188eb)

1 / 68      (Adware)

1 / 68      (Adware)
winzip.exe (by setupprocess)  (983124afeb09fe1cf35ca19c52b89eea)

1 / 68      (Adware)
picasa.exe (by Rapiddown)  (6531a88938b6c6b0fec0271e7fa5773b)

1 / 68      (Adware)
avast! free antivirus.exe (by setupprocess)  (06252b7a1c34abe5ad41e0d0c8034431)

29 / 68    (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
internet explorer 9.exe (by setupprocess)  (7253f1818f24fa02ce84ab51b50338c1)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
doraemon.exe (by setupprocess)  (30ab01a16a14fe4c0657d101404fd74c)

1 / 68      (Adware)
windows live mail.exe (by Rapiddown)  (51e24103f0fd3210ae227c472fa301e4)

1 / 68      (Adware)
glsl shaders indicator 1.7.2.exe (by setupprocess)  (86f66d3f5d19491db7605d35205123cc)

1 / 68      (Adware)

35 / 68    (Adware)

1 / 68      (Adware)
free live tv.exe (by setupprocess)  (99647d62ae78da22b3f13d101097636c)

1 / 68      (Adware)
google chrome.exe (by Rapiddown)  (640b53c5a1573c560f067b806b1f2e91)

1 / 68      (Adware)
skype.exe (by setupprocess)  (ea5c85defaf2bd150e0dbb1fd05d6d22)

1 / 68      (Adware)
minecraft.exe (by setupprocess)  (c80b47f726f5d7bb716c77846161b86a)

1 / 68      (Adware)
winamp.exe (by setup process)  (5a5518f6cef6ef5e74fafeea90ce24c2)

1 / 68      (Adware)
avast! free antivirus.exe (by setup process)  (3f2b0593c0e5d65d5d1cc8b5c1fa7aba)

1 / 68      (Adware)
outlook express.exe (by setupprocess)  (cbcd9708a4d56017a5d119092e4c415a)

1 / 68      (Adware)
outlook express.exe (by setupprocess)  (0176bfd4192df662446ad35dc2f6dffb)

1 / 68      (Adware)
photoscape.exe (by setupprocess)  (fab0b7dc2333d1869d80e09915e241fa)

1 / 68      (Adware)
utorrent.exe (by setupprocess)  (1e76e7b97842d52f19a2114286f67ea7)

 
Latest 30 of 727 files

Downloads URLs for files signed by SETUPPROCESS.

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

35 / 68    (Adware)
http://dl.d0wnpzivrubajjui.com/n/.../FLV_Media_Player.exe  (e4faedf51e6499cd79fe231f0bdc161a)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

The following publishers (by Authenticode signature organization name) are related.

Remove SETUPPROCESS Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to SETUPPROCESS by DigiCert Inc on November 26, 2013 with the serial number '0a8abfc7c80d0c2f0a3a89cf6139a91d'.