xwidget_setup.exe

XWidget

XWidget Software

The application xwidget_setup.exe, “XWidget Setup ” has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from zr3mzw.bn1302.livefilestore.com.
Publisher:
XWidget Software

Product:
XWidget

Description:
XWidget Setup

Version:
1.90

MD5:
c4d0aec190460ad4437875ebe9876ace

SHA-1:
25ba5d46cc9ae9842a62331910ccc5470f32ba9d

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
7/20/2025 7:30:09 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallMonetizer.AQ
8.9540

F-Prot
W32/FakeInstall.A.gen
v6.4.7.1.166

VIPRE Antivirus
Trojan.Win32.Generic
27356

File size:
8.8 MB (9,276,321 bytes)

Product version:
1.90

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\xwidget_setup.exe

File PE Metadata
Compilation timestamp:
12/20/2011 3:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:fhfMsIwh2Evi4yiVyI5ZlzKHB08JsiH3lkdkstO13/BvrKz:fhfGwUEaFi8I5WHa8J7VekvrK

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9951

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file xwidget_setup.exe has been seen being distributed by the following URL.

Remove xwidget_setup.exe - Powered by Reason Core Security