transparentwindows-setup.exe

Tucows Inc.

The application transparentwindows-setup.exe by Tucows has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from files4.mirror1.info and multiple other hosts.
Publisher:
Tucows Inc.  (signed and verified)

MD5:
877d7cb53eabd052e0a2ed585f746839

SHA-1:
a9deda742a2f0c40e585fdf21c0adbf72c593d94

SHA-256:
69ac4ba7e8c0b2735103978e14d77919ae567448fa0c56d69c6e18db52e3eebf

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/20/2024 12:04:10 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Tucows
2015.0.3254

Dr.Web
Adware.Downware.2220
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
7.0.302.0

F-Secure
Spyware: Adware:W32/WebInstallBundle
5.13.68

Norman
InstallCore.WQEC
11.20141220

Reason Heuristics
PUP.Installer.Tucows
15.1.21.15

VIPRE Antivirus
Threat.4783369
35418

File size:
1.2 MB (1,213,200 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\transparentwindows-setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/20/2013 5:00:00 PM

Valid to:
8/20/2016 4:59:59 PM

Subject:
CN=Tucows Inc., O=Tucows Inc., STREET=96 Mowat Ave., L=Toronto, S=Ontario, PostalCode=M6K 3M1, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4A452F2DD2EEA6072814A28EF2F01AEE

File PE Metadata
Compilation timestamp:
6/22/2012 11:07:51 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Bg44A3isJxwzKcfYXQGByv/LmYeicKLIi8CtcRxEi9uqhRkLC0GzGD:i4zEKcfYAGgv/i5i5aRWi9ukqJGz4

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
6.3372

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file transparentwindows-setup.exe has been seen being distributed by the following 3 URLs.

Remove transparentwindows-setup.exe - Powered by Reason Core Security