setup__2140_il19647.exe

mlru

SPRT

The application setup__2140_il19647.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup. The file has been seen being downloaded from www.panningmanybanded.site.
Publisher:
SPRT

Product:
mlru

Description:
smart install

Version:
56.222.188.22

MD5:
ed64cb3901b77f2f5b104cfe66e10a07

SHA-1:
a26a6e2341c38d91040ca963471f898784301944

SHA-256:
b89939aaf542807437b23e7f3859a2a368296d56e35ae1670512ff7f598d2c40

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
6/29/2025 11:07:46 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.InstallMonetizer.SPRT.Installer.Meta (M)
16.5.10.5

File size:
1 MB (1,079,808 bytes)

Product version:
56.222.188.22

Copyright:
Copyright 2016

Trademarks:
SW Good M

Original file name:
osetup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\setup__2140_il19647.exe

File PE Metadata
Compilation timestamp:
5/10/2016 9:27:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
24576:n2JBRZhG057OFBUVSM528FzyhmLny51gnqzE43:CvvGY8Ba3FzyhmLy51CqY2

Entry address:
0xC2D9

Entry point:
E8, 39, 5F, 00, 00, E9, 39, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 98, 56, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B, F1, E8, 5F, 00, 00, 00, C7, 06, 98, 56, 42, 00, 8B, C6, 5E, 5D, C2, 04, 00, 55, 8B, EC, 56, FF, 75, 08, 8B...
 
[+]

Entropy:
7.6392

Code size:
135.5 KB (138,752 bytes)

The file setup__2140_il19647.exe has been seen being distributed by the following URL.

Remove setup__2140_il19647.exe - Powered by Reason Core Security