tsasetup.exe

File Type Assistant

FTA APS

The application tsasetup.exe by FTA APS has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. This file is typically installed with the program File Type Assistant by Trusted Software which is a potentially unwanted software program. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
FTA APS  (signed and verified)

Product:
File Type Assistant

Version:
2014.3.25.0

MD5:
a02ac2e8c5371687d72a1c5f5decf85f

SHA-1:
da54389ea063f8d7a26e3cb39aa09032e4dbd213

SHA-256:
64ec24827934ef50cbaa4531f2c23e686f8f0c34ad6a2e3d8fab5a0c7146aa71

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 8:42:46 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/FileTypeAssistant.A potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.AC.gen
v6.4.7.1.166

Reason Heuristics
PUP.Installer.FTAAPS
15.4.24.0

File size:
1.4 MB (1,513,968 bytes)

Product version:
2014.3.25.0

Copyright:
Copyright © 2010-2014 Trusted Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\Program Files\file type assistant\tsasetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/4/2014 3:00:00 AM

Valid to:
4/5/2015 2:59:59 AM

Subject:
CN=FTA APS, O=FTA APS, STREET=Bysoestrade 2B st., L=Holbaek, S=DK, PostalCode=4300, C=DK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A8BF96664C5D11A73AA0900284E705CE

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Inafk8DdvTz5eMxApmW8I13kj+0abMId4h1SrjBQRHrfMWiO/Qa2RYcBP+gFGC0m:IaskP5eUX3IRuvoW1elQ9Qq4aIBt6b36

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Entropy:
7.9903

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Scheduled Task
Task name:
ProgramRefresh-ATFST

Trigger:
Daily (Runs daily at 1:56 PM)


The file tsasetup.exe has been discovered within the following program.

File Type Assistant  by Trusted Software
File Type Assistant is typically bundled by various 3rd party software through modified installers of generally free open source software using the InstallIQ downloader.
www.trustedsoftware.com/utility-software/free-file-viewer.html
74% remove it
 
Powered by Should I Remove It?

Remove tsasetup.exe - Powered by Reason Core Security