Adobe Flash Player Setup.exe

Adobe Flash Player

Install Helper

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application Adobe Flash Player Setup.exe by Install Helper has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer. It is also typically executed from an Internet Explorer cache folder.
Publisher:
Install Helper  (signed and verified)

Product:
Adobe Flash Player

Version:
3.0.0.105

MD5:
e6e758872aefc06daf23cc2911779713

SHA-1:
d573053d009d95dfa70798a437e20b1f3846a1fd

SHA-256:
1837a1a37d10c180e8f788aefbb938e7656acb02009485a5a77873fe6363606d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/30/2024 10:13:12 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia (M)
17.3.6.18

File size:
961.1 KB (984,192 bytes)

Product version:
3.0.0.105

Copyright:
(c) Install Helper

Original file name:
Adobe Flash Player Setup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\adobe flash player setup.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/20/2015 10:00:00 AM

Valid to:
5/20/2016 9:59:59 AM

Subject:
CN=Install Helper, O=Install Helper, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0575634D1B3373331074EB7C4751AB12

File PE Metadata
Compilation timestamp:
6/14/2015 12:33:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 10, 49, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0515

Developed / compiled with:
Microsoft Visual C++

Code size:
574.5 KB (588,288 bytes)

Remove Adobe Flash Player Setup.exe - Powered by Reason Core Security