3dem_setup.exe

InstallShield

Visualization Software LLC

The program is a setup application that uses the InstallShield Setup installer. The file has been seen being downloaded from www.pancroma.com and multiple other hosts.
Publisher:
Macrovision Corporation  (signed by Visualization Software LLC)

Product:
InstallShield

Description:
InstallShield (R) Compact Installation Engine

Version:
14.0.0.223

MD5:
c6741f29229b84c2d610450e46378949

SHA-1:
0356e914d82f809c2f95d30de27887441b579992

SHA-256:
d9cb4b25211d7c5037415e41e05b12387b91360adf4608bb969f7262ae219842

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/26/2024 8:35:53 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/PECompact
7.1.1

File size:
4.1 MB (4,340,304 bytes)

Product version:
14.0

Copyright:
Copyright (C) 2007 Macrovision Corporation

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Installer:
InstallShield Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\3dem_setup.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
10/21/2007 7:00:00 PM

Valid to:
10/21/2010 6:59:59 PM

Subject:
CN=Visualization Software LLC, O=Visualization Software LLC, STREET=76 Mourning Dove Drive, L=Stafford, S=VA, PostalCode=22554, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00E3EF445530FA08E00C5DC7D22B2CDE38

File PE Metadata
Compilation timestamp:
7/16/2007 10:02:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
98304:EmurNrWXEr/VLl1QLS49W/RTLbiBV9NTNAsGXpNhv8Lt0vdGX3j:HsrWUr/VLMLS49mBfq2sG98AU

Entry address:
0x1000

Entry point:
B8, B8, 78, 42, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 23, 41, A7, F7, 7F, 41, B5, 8B, 26, 46, 58, 99, D6, 2F, FC, E1, F1, 9D, 94, 48, 00, 4A, F8, 00, F5, EA, D4, C1, 0F, 05, 3C, 23, 70, AE, 68, 86, 88, 3E, 78, E8, 80, 09, 36, 8C, 50, 2D, F8, F9, EF, 67, CD, 18, 7F, DF, 9C, 17, 80, EE, B8, 17, E8, 03, 42, 5A, 28, C2, 1F, 8D, 9B, 81, 20, DF, 3F, F6, C2, 75, B9, 41, F2, 56, 22, 5D, 0D, B3, 50, 87, 88, 41, 57, B4, 0A, BC, 43...
 
[+]

Entropy:
7.9995

Packer / compiler:
PECompact v2

Code size:
110.5 KB (113,152 bytes)

The file 3dem_setup.exe has been seen being distributed by the following 3 URLs.

http://www.pancroma.com/.../3dem_setup.exe

Scan 3dem_setup.exe - Powered by Reason Core Security