setup.exe

Cash Buyer Media

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe by Cash Buyer Media has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer.
Publisher:
Safeguarded Swift System Installer  (signed by Cash Buyer Media)

Product:
Safeguarded Swift System Installer

Version:
60.6.6.1765

MD5:
0427acb4ec8f56d8ed2062133ce01a79

SHA-1:
77affdf0061e043ed70d1c0243dd36c97b75187f

SHA-256:
22725a2aa0c223b97e45c35035d024c63d3487417138e6dcce8b8077cb647739

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 1:19:23 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
2014.9-151004

Kaspersky
not-a-virus:Downloader.Win32.DownloAdmin
14.0.0.1325

Malwarebytes
PUP.Optional.DownLoadAdmin
v2015.10.04.09

McAfee
Virus.DownloadAdmin
5600.6622

Microsoft Security Essentials
Threat.Undefined
1.207.757.0

Reason Heuristics
PUP.Vittalia.CashBuyerMedia.Bundler (M)
15.9.9.23

VIPRE Antivirus
Threat.4721115
43798

File size:
756.8 KB (774,936 bytes)

Product version:
60.6.6.1765

Copyright:
Copyright (C) 2015

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
9/7/2015 1:46:46 AM

Valid to:
9/7/2016 12:41:42 AM

Subject:
CN=Cash Buyer Media, O=Cash Buyer Media, L=San Francisco, S=California, C=US

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00BB2FEC76C4F052D1

File PE Metadata
Compilation timestamp:
8/26/2014 2:45:55 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:9VepajkAGKIHZW2yBFGnk7d5qddMWFvW2LPp1tFChspvmtREjCTM:GzOyIFG+5qddDhH3oVLEjCTM

Entry address:
0x1EFBE0

Entry point:
60, BE, 00, 60, 53, 00, 8D, BE, 00, B0, EC, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
744 KB (761,856 bytes)

Remove setup.exe - Powered by Reason Core Security