wgbsetup.exe

Proinstall Applications SRL

The application wgbsetup.exe by Proinstall Applications SRL has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Proinstall Applications SRL  (signed and verified)

MD5:
6ea7822846b0e3715292502f07df22bf

SHA-1:
20375c1249834beaa271179995445ca09ea8c94d

SHA-256:
f3e3f06ddad29ce617e6afbf988d5756afb33ecf8a7c5b2a01cafb0e77db4975

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
3/11/2026 11:16:04 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.9446
9.0.1.097

NANO AntiVirus
Trojan.Nsis.Downloader.doczdj
0.30.10.952

Reason Heuristics
PUP.Installer.ProinstallApplicationsSRL
15.4.7.2

VIPRE Antivirus
Threat.5066599
36666

Zillya! Antivirus
Downloader.Genome.Win32.53515
2.0.0.2128

File size:
230.9 KB (236,392 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\wgbsetup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/16/2015 8:00:00 AM

Valid to:
2/12/2016 8:00:00 PM

Subject:
CN=Proinstall Applications SRL, O=Proinstall Applications SRL, L=Bucuresti, S=Bucuresti, C=RO, PostalCode=030964, STREET="Bd Decebal Nr 25-29,", STREET="Etaj 9, Camera A Sectorul 3", SERIALNUMBER=33860761, OID.1.3.6.1.4.1.311.60.2.1.3=RO, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
03C5A27C419AE0D26C91B788E52C93E6

File PE Metadata
Compilation timestamp:
12/6/2009 6:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:fQIURTXJqORfcc4VQgH1wOzUUUcI/CUAJkAoG0z/ZMh0FyzA554:fs4ORt4nH1zf5VUAmASzyPu4

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.0680

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove wgbsetup.exe - Powered by Reason Core Security