yusetup7.exe

Your Uninstaller! 7

URSoft, Inc.

The application yusetup7.exe, “Your Uninstaller! 7 Setup ” by URSoft has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from download.ursoftware.com.
Publisher:
URSoft, Inc.   (signed by URSoft, Inc.)

Product:
Your Uninstaller! 7

Description:
Your Uninstaller! 7 Setup

Version:
7.4.2012.5

MD5:
b82099694a0c94baaa97a780c0e97104

SHA-1:
737447767a1cf7347df3800e4bef63c90c8fe3af

SHA-256:
42330b844656f71bf19b5f80622c72490c83e3a47d06b170a909cb24bd8a8b7b

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/26/2024 9:51:20 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Toolbar.Babylon
8.8401

Reason Heuristics
PUP.Optional.URSoft.Installer
15.6.19.11

File size:
7 MB (7,321,944 bytes)

Product version:
7.4.2012.5

Copyright:
Copyright © 1998-2012 URSoft, Inc.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\?????? ???? ??????? ?? ?????? ?? ??????\yusetup7.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/6/2012 1:00:00 AM

Valid to:
3/7/2015 12:59:59 AM

Subject:
CN="URSoft, Inc.", O="URSoft, Inc.", STREET=7241 W. Addison, L=Chicago, S=IL, PostalCode=60634, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2D52C7CF5E69A633AC3AED0E78F988DC

File PE Metadata
Compilation timestamp:
12/25/2011 10:18:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:IViLGkMuhflulrjdG9COt1bTOxV6dFeE1okQlw:kiLGPptjdG9COTTdFeMd

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, B0, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, B0, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9851  (probably packed)

Code size:
84 KB (86,016 bytes)

The file yusetup7.exe has been seen being distributed by the following URL.

Remove yusetup7.exe - Powered by Reason Core Security