rSetp.dll

The file rSetp.dll has been detected as a potentially unwanted program by 27 anti-malware scanners.
Description:
ProcessMon

Version:
4.0.8.01

MD5:
a0840b6ee26791ef32068e0629bf9801

SHA-1:
574bb311577db0707fcf413f5f6f65214a17413c

SHA-256:
706f10b3a6c08f756fd758a23e882ec6971bab470e2d67b3ddddf4ba43d17e34

Scanner detections:
27 / 68

Status:
Potentially unwanted

Explanation:
Uses the DomainIQ download manager to bundle additional potentially unwanted software without adequate consent.

Analysis date:
4/18/2024 6:55:28 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.922288
864

Agnitum Outpost
PUA.DomaIQ
7.1.1

AhnLab V3 Security
Spyware/Win32.Limitail
2014.06.24

Avira AntiVirus
APPL/DomaIQ.Gen
7.11.156.100

avast!
Win32:DomaIQ-CK [PUP]
2014.9-140923

AVG
DomaIQ.S
2015.0.3342

Baidu Antivirus
Adware.Win32.DomaIQ
4.0.3.14923

Bitdefender
Adware.Generic.922288
1.0.20.1330

Emsisoft Anti-Malware
Adware.Generic.922288
8.14.09.23.03

ESET NOD32
MSIL/DomaIQ (variant)
8.9989

Fortinet FortiGate
Adware/MSIL_DomaIQ
9/23/2014

F-Prot
W32/DomaIQ.E.gen
v6.4.7.1.166

F-Secure
Adware.Generic.922288
11.2014-23-09_3

G Data
Adware.Generic.922288
14.9.24

IKARUS anti.virus
AdWare.DomaIQ
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.180.12498

Kaspersky
not-a-virus:AdWare.MSIL.DomaIQ
14.0.0.3207

McAfee
RDN/Generic PUP.x!bt3
5600.6998

MicroWorld eScan
Adware.Generic.922288
15.0.0.798

NANO AntiVirus
Trojan.Win32.DomaIQ.cwydit
0.28.0.60475

Panda Antivirus
Trj/CI.A
14.09.23.03

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
9.14.14.00

Sophos
DomainIQ pay-per install
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0PEC14
7.2.266

Trend Micro
TROJ_GEN.R0CBC0PEC14
10.465.23

Vba32 AntiVirus
AdWare.MSIL.DomaIQ.amvu
3.12.26.3

VIPRE Antivirus
DomaIQ
30586

File size:
262 KB (268,288 bytes)

Product version:
4.0.8.01

Original file name:
rSetp.dll

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\weed539.tmp

File PE Metadata
Compilation timestamp:
3/1/2014 1:07:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:hQoRfy7Q3uKuSNe6EqfhYdTgrIXi6qJ+dLSgviwT1Y2ZTkhbbsK7j3BO8xwNtq:hQoRmQ3BxbEhlgB+djvXHQ5bjVO8x

Entry address:
0x3F1FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3092

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
245 KB (250,880 bytes)

Remove rSetp.dll - Powered by Reason Core Security