bestremovaltool_setup.exe

Best Removal Tool

Guangxi Nanning Qiwang Co. Ltd.

The application bestremovaltool_setup.exe, “Best Removal Tool Setup ” by Guangxi Nanning Qiwang Co has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. This file is typically installed with the program Best Removal Tool by www.bestremovaltool.com. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from www.bestremovaltool.com and multiple other hosts.
Publisher:
www.bestremovaltool.com   (signed by Guangxi Nanning Qiwang Co. Ltd.)

Product:
Best Removal Tool

Description:
Best Removal Tool Setup

Version:
6.3.3.9

MD5:
26b15b2db2eed3d4579074198541b940

SHA-1:
2f6869bb025a883669d091b00248a7da83830ebe

SHA-256:
4044505b81ceaa4544d77f4ab93e3ce5e3a36a8d36f66389eb9b579754928c4a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/26/2024 6:27:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.GuangxiNanningQiwangCo.V
14.3.11.12

File size:
2.5 MB (2,631,592 bytes)

Product version:
6.3.3.9

Copyright:
Copyright (C) 2006-2012 Best Removal Tool, Inc.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\bestremovaltool_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/29/2011 1:00:00 AM

Valid to:
6/29/2014 12:59:59 AM

Subject:
CN=Guangxi Nanning Qiwang Co. Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Guangxi Nanning Qiwang Co. Ltd., L=Nanning, S=Guangxi, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
058EFD81CFC178B930CAA249710DE3B1

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:q2J90AODygFWDLn077PIVk9di6GrEwlMMKrjmTvT1y4l4ZLyeZbTZkkDZT:rJmD1FbYmT8M1mTxy4l4ZLykbTZND1

Entry address:
0x9A58

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 6E, 96, FF, FF, E8, 75, A8, FF, FF, E8, A0, CA, FF, FF, E8, E7, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, 0B, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, D4, A0, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, AC, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, 1F, 97, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file bestremovaltool_setup.exe has been discovered within the following program.

Best Removal Tool  by www.bestremovaltool.com
www.bestremovaltool.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file bestremovaltool_setup.exe has been seen being distributed by the following 2 URLs.

Remove bestremovaltool_setup.exe - Powered by Reason Core Security