fl_setup.exe

Fileadventure

This is published and distributed via an Adknowledge's advertising supported (adware) software installer. The application fl_setup.exe, “Swift Installer ” by Fileadventure has been detected as adware by 29 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from dolr8irx.pn-installer3.com.
Publisher:
Swift Installer   (signed by Fileadventure)

Product:
Swift Installer

Description:
Swift Installer

Version:
2.4.8.1

MD5:
0886ba626aab08128f12278a5d6bafba

SHA-1:
11b02308bb82b09c295a75ea6350d6c6b9ee57cf

SHA-256:
9ccfeb79a8ce5715b98423fea54bf8dd55f129d7e2cbcefaf1c6b622f57b7011

Scanner detections:
29 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 1:54:20 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.35
6532367

AhnLab V3 Security
2014.12.10

Avira AntiVirus
ADWARE/iBryte.Gen7
7.11.185.204

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150317

AVG
Adware AdPlugin.BWT
2014.0.4257

Bitdefender
Gen:Variant.Adware.Strictor.71370
1.0.20.380

Clam AntiVirus
Win.Adware.Strictor-362
0.98/20197

Comodo Security
Application.Win32.Ibryte.NW
20315

Dr.Web
Trojan.DownLoader11.49526
9.0.1.076

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.35
9.0.0.4799

ESET NOD32
Win32/Adware.iBryte.BR application
9.7.0.302.0

F-Prot
W32/A-a1a6e5b1
v6.4.7.1.166

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.13.68

G Data
Win32.Adware.IBryte
15.3.24

herdProtect (fuzzy)
2015.6.23.7

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.186.14280

Kaspersky
not-a-virus:AdWare.Win32.iBryte
14.0.0.2332

Malwarebytes
PUP.Optional.Fusion.A
v2015.03.17.01

McAfee
IBryte-FSO
5600.6823

MicroWorld eScan
Gen:Variant.Adware.Kazy.491026
16.0.0.228

NANO AntiVirus
Trojan.Win32.Buzus.djslbz
0.28.6.63850

Norman
Gen:Variant.Adware.Strictor.71370
11.20150317

nProtect
Trojan/W32.Buzus.339832
15.02.25.01

Panda Antivirus
Trj/Genetic.gen
15.03.17.01

Reason Heuristics
PUP.Installer.Fileadventure
15.3.17.13

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4778314
34232

Zillya! Antivirus
Trojan.Buzus.Win32.123141
2.0.0.2081

File size:
331.9 KB (339,832 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) Swift Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\fl_setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/13/2014 7:00:00 PM

Valid to:
7/14/2015 6:59:59 PM

Subject:
CN=Fileadventure, O=Fileadventure, STREET=4600 Madison Ave FL 10, L=Kansas City, S=Missouri, PostalCode=64112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2EF279A57EB2CCFE0FCD97FC0F239ADE

File PE Metadata
Compilation timestamp:
12/4/2014 1:00:26 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
3072:+5dlWaI3qsdtco9QUGIVC9RMWApKwev17Eblkz25Xg74VBrbQ3k5L8I0UjZ299ya:dP3jzNInMWpw1bH674VBrbQmLzZM9jBt

Entry address:
0x185F3

Entry point:
E8, 5A, A7, 00, 00, E9, 78, FE, FF, FF, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 84, A6, 43, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 84, A6, 43, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F...
 
[+]

Entropy:
5.9352

Code size:
184 KB (188,416 bytes)

The file fl_setup.exe has been seen being distributed by the following URL.

Remove fl_setup.exe - Powered by Reason Core Security