freefileviewersetup.exe

Baromaroro

The application freefileviewersetup.exe, “Baromaroro Setup ” has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Product:
Baromaroro

Description:
Baromaroro Setup

MD5:
89a4ef099a49c40aa2c0d1048cf1fc7f

SHA-1:
1f4671d1b7dd13f3d77782d8ff264373f68e72b3

SHA-256:
543cb16387a1478bcdf0d2e437ecb7e994806825dfc706bb1cc9a5e256c58cc7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/28/2024 12:33:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.RE11 (M)
16.5.16.9

File size:
1 MB (1,052,999 bytes)

Product version:
2.5.8

Copyright:
Fast Wizard Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freefileviewersetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:zHsXdMZjAomR9Ev5OusSFoaa9x1rk8+rzEv++0uacyC:zMtMZjAlHEvOSFodNrP+rZ+gG

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, BF, A9, FF, FF, E8, 5E, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9186

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file freefileviewersetup.exe has been seen being distributed by the following 50 URLs.

http://www.chucklebodybits.com/WVl6OTRQV1k1VVdONmFHUXlUbTkzTWxsd2RrTWxNa0pRZVVKRFNXWjVkSEp2ZFhCallsTnZaMm80VEU5dFptbEZTU1V6UkNaalBVSmxXamN3VDA4ME4wVnZaVFJGTnpWd05ISTBRWEpWTVVGM1RXeDZla3hEWkU5VmNYWktkWFE0SlRKQ1ZWSTBUemRqT0haVGRWZzRjM1UxYkZWSU5HWlNXRE5IWlU1SE5sZFNkMUZsV2t4MFR6QjNWMkZWVkVOMU5USlJNelJOUTFobmNXRlhVRFZwV0dONmRFMVZUMUJHZW1OcWVIazRWM3BLVW1wUGVIUklaWGN3YTJOSGRHRXdSVEV5ZVZaMVpsZEhRWFJIT0RSM0pUTkVKVE5FSm1VOU1DWmtiM2R1Ykc5aFpFRnpQVVp5WldWR2FXeGxWbWxsZDJWeVUyVjBkWEF1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbVp5WldWbWFXeGxkbWxsZDJWeUxtTnZiU1V5Um1SdmQyNXNiMkZrY3lVeVJtNWxkMlZ6ZEM1bGVHVT0=

http://www.currentappdownloads.com/WVl6OTRQU1V5UWtoeU5XWndlVGh6Y0Zsd2N6bDVUVzFIVFdOMUpUSkdNSFJ3WXpkWU5WRkxlbmNsTWtKdFlVbFJUR3R0YldjbE0wUW1ZejEzVldGTldVeFJkV3hMWXpadmJrUTNPWHBIYjFSWVNqTm5XamxaV2pOcGVVcFlPRkJDWW1zM2FUWlNSbE5QV1hGNVJpVXlRbTF4VXpsUlMyd3pZVUZvUWt0VFVrZE5lVWMwUTJFMVprOXFRbEJQU0ZCcVFrWk1aa2tsTWtKNGFrRm1KVEpHYTJVM2NsUnphVzlaYkhSQmFVcFBWV3hNVWtKVGJtMXhZemRJVXpVMGVVRjRkWEZZWVhNd2JWQktaMll6YTBJMVVHcEtkemRYVkhjbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlSbkpsWlVacGJHVldhV1YzWlhKVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VabkpsWldacGJHVjJhV1YzWlhJdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

http://www.capitalapplicationclear.com/WVl6OTRQWEpVZFVKRmMyWXlZV3B5VERsTlEwSm1jV1UzTTJoc09HUlRiQ1V5UWxKTFRrUnBVak5aYXlVeVJqbExha0pSSlRORUptTTllVWRNWjBaU1JITm1PSEpKVVVRd1VucEVjakUwYjBkRGVrRkhKVEpDY1hoNmVHMHliRUpZT0ZCeFJEWnRORVZaWjNGM2NuQnNVMGcxTWtjbE1rWktVWEo2TXpGSlIzQndhRzRsTWtZMmVsbGxjbGRyUmxKcVZDVXlRa3BWTjNGYWNtOVlTMmMzWm04d2JXdFNjRTgyWlNVeVJtVXhabGRRVUU1NlUzUjJiVk5KTVZWdFEyVlNVbTQyWWxaWFIwRmxWVWxxY0dRMU1pVXlSbWx6U21kdFJ6ZDNKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVaeVpXVkdhV3hsVm1sbGQyVnlVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG1aeVpXVm1hV3hsZG1sbGQyVnlMbU52YlNVeVJtUnZkMjVzYjJGa2N5VXlSbTVsZDJWemRDNWxlR1U9

http://www.conecptmegadelivery.com/WVl6OTRQV2RPUVVSNVJVdERRVEpQWlZGVVZWRTBSWEJJVnpWNVptSTFNWFp4TW5aNmNWRTBUWEJsV1drbE1rWTRkeVV6UkNaalBYRjFjekJEVkZwU05GQlpaMUprTkV3MllraEhjekIzVkc5Wk1EQlJXRlZvVDNweEpUSkNPSEZVVGtoRlQwWnVlSFYyU1U5cGNtTlpKVEpHVUhWc1pTVXlRbElsTWtaMFMyaHFja3BrTlhSUlJHaGhWV042Y25vMlIweDNjVzlNV1ZwMFVEZDVkREJvTVhsQ1EyNU1VM0Z5YTFSdlkwcG1kV2xwVlZCRmRFSkRkbTBsTWtaSGMzTjNkMnh2ZUZGb0pUSkNPRUYwUzNVM2FUUWxNa1k1UTJKeVFtMVJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVaeVpXVkdhV3hsVm1sbGQyVnlVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG1aeVpXVm1hV3hsZG1sbGQyVnlMbU52YlNVeVJtUnZkMjVzYjJGa2N5VXlSbTVsZDJWemRDNWxlR1U9

http://www.bundlecentralsign.com/WVl6OTRQWGhWWWxkTFNWSkhTblpSWTFCaVNWVk1RVFF5Y2pVbE1rWnhUbEpRY0VWd1pVSkhSRnBPYVdNeGJVNWtTU1V6UkNaalBWZHBZVVpJV0VneWNsaHRha3dsTWtKVVZYTmhOVTVGYW5SUVpXOUJjblpSZENVeVFqaFhNR2xQT1VSeU5taFNVelp1YjI5NE1rSkJjRzV3WTFKVldtcHZaRWhESlRKQ09WbERZMWs0VVhscmRFY3dSelpQUjNvMmRrbHpVMWMxU0hseGIxZG1OMmQzVkhVMVEwTkdSRmczVkc5cmRWRndTRTVzWm5wSVlucHFVRTlTTUVwUWRXbDBOa1ZWVDJScmIySkdXRU1sTWtKMlJpVXlSakJJYUZFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlSbkpsWlVacGJHVldhV1YzWlhKVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VabkpsWldacGJHVjJhV1YzWlhJdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

http://www.bestsharehead.com/c?x=57gwHNst 3YtSYZrtehGcnynUHMF2UwFGaciB ZkTVo=&c=cSerbzLyqC5PD899t7wH9MFGWkuqWhujtzbcVVs6QcguoxXUEubUuti4M/Rxdwbmg6RUu/XeEPdgOmXjCOPL6MxbmdRsjr Wg4jBvXyxV/zGStWwo23e1EXpVJ3Qh f1qQe7qbSshphIw0rquoQgiY6jF69JYlA2KXM/niosmyEHCSqTwQysoCJHZBXeEeL2&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.townflashranch.com/c?x=gW infoGjbnDTTyP7zoC9nPrw/O8gMHyV2tPV8EbVpU=&c=iktg2VzQH6xcuWhtM/JJhLqRYhfEMLT8r5DTmQrGfOQEuVUUSn5dqPV55roDT99bWG7UsxF0nCXkksFlu1I5Ym2EEgykoGr0zIqb2sPFl2bvw57Z9SvEnVdFOWA0tg8/FlOcwnXAwcucyG/VbiS38uhCvYsSKJt6Yqhmkdp38HXkY45VajqsneQZilLKp/Ia&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.apptownnow.com/c?x=yzN4jCLsJQu5dJBjNoDKYXu7JShD7BwiLXn qQZnYco=&c=AJAgyut5ZHhtKC8J22kUbFbEUeu9EXKNv4ZGVluZzcQkL2ixsEpdkgNZsS tTQm/xGjpIDusbylOLcUG2xI0DKZoUVK99XyhA5 rQeHMKsSNvy 1giyRzwD56V33wv/JHbS3td7eUGoYWGYp8lurppU3xLRSmt6b7HBmzlFktb4XHxnkscmyYW1QGy3b30QK&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.bestsharehead.com/WVl6OTRQVVIyUm1RbE1rSnViV3MwVldOdEpUSkdUM1JtWjJWdFIzaDBWbnBSYm5WSk9IUnpWRzlSZUZjMU4xUXlVMkp2SlRORUptTTlRM2gzVTFKMVRXNWxTVFJSZDJOSWFuRlpUM2RXYVhFek1YVmtTR2hGYmxveFlWSlJiR3N5WlhrNE9WSktUMFpRV0djNVpDVXlRa2dsTWtaNWIzWlVjbXgxVWxkRlQwb2xNa1oxZEdodk9WTndhV3RJTjIxdVkwa3dTVTlHUjNkamVIbDVhVGRTVkZsTFZrdGFlWFZrTVZKUlJTVXlSalZOWldkclQwZG9aMWgwSlRKR2JXNUZaVWN3V2tWRlRURnZlbmRPTmlVeVJucGFOM0JrYWxsNWFWcFJKVE5FSlRORUptVTlNQ1prYjNkdWJHOWhaRUZ6UFVaeVpXVkdhV3hsVm1sbGQyVnlVMlYwZFhBdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG1aeVpXVm1hV3hsZG1sbGQyVnlMbU52YlNVeVJtUnZkMjVzYjJGa2N5VXlSbTVsZDJWemRDNWxlR1U9

http://www.chucklebodybits.com/WVl6OTRQVGxLVm01emVEYzJWVWRhYkdGSE1VOGxNa0kxZURoTVJpVXlRbHBCWnpKR1UwRTRlamtsTWtKS1VqWklXaVV5UWxaa05DVXpSQ1pqUFdkV04zSmFVM0ZRUWpsNWQyZDJkR1Z3Y3pGTGRtYzRkalJ2WVRsS2NXSlhTbVpLVG1KdFVqVkRkbFZQVURrMU1UbFlUWFl3WTFaUlkycDFTR0ZZVUZweFJHZzJVbVZPWWlVeVFrNUpkVnBPYUU5cmJISTVNRk5ST0c4NGIxSXliVTlZV0RscU56ZE5aR2wwSlRKQ1JVWkRVRlJGWVZGVFZuSnlaVkIyTm14UVdFOU1TMGhXVUhZd2RHWkJUWEZPTVVsdlduVkRWME4xT0VFbE0wUWxNMFFtWlQwd0ptUnZkMjVzYjJGa1FYTTlSbkpsWlVacGJHVldhV1YzWlhKVFpYUjFjQzVsZUdVbVptRnNiR0poWTJ0ZmRYSnNQV2gwZEhBbE0wRWxNa1lsTWtaM2QzY3VabkpsWldacGJHVjJhV1YzWlhJdVkyOXRKVEpHWkc5M2JteHZZV1J6SlRKR2JtVjNaWE4wTG1WNFpRPT0=

http://www.currentappdownloads.com/c?x= t2E6v3ZUTY4tZDZbZ8oNYg9d0jwcVsljAAUHOCAKLQ=&c= SWtvR3tys7eO6RZpMhA6zyHbC66Sm7USQyfi aXapIYs6vQqFWghtiNYFTVqhR QFzIdWGcZSRduNwMO93tAIkbQR7 guttgRQcjtnJpsOWY8kSVPCL1sFHxcYlPQJ4NENuiQQJAtWyFgCTIMkME9Nf7H/F5fll6xniMtSaPQlI2FkoEiNDM2puMdX4ntcU&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.capitalapplicationclear.com/c?x=2kqk0510ip1X5RQ1JDkBesVf18KwdM hB2H8ph1ZDVo=&c=akJW2wGNWIuI1r8XkWp05ihZHP6qv3T6A5TRIOrG2HPSagapt4RJkHabpJ6KKXZrfI60tkqqtQwEQUrQH6DyQKJ9kXr2oFaqmIh0At08LDaIuTNa/69novrgzejD XTO5OeTOLCq i4LUWedL1TIzkA2/A7w5PlfzHE7EZMoZ09dQVZ2/i8if8EKdYJf6VmX&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

http://www.worldbundlegift.com/c?x=Lr6e9CEEBVdymU8OxDoD/NmcChjDtyDlBg56py c6ck=&c=cb75ZcTfDnbA7o2o SiHcNFA0pjw vZVccLSCDtw1jVyZu2czLgnZO7r1YxX4KAqWjHRCOKqD9MLe4 5/uQ7KutzfaGZjbiNRd8fBrKq zHEp q9VOYCRMoBDpVU kUy/K7xj6YgGvjC7tThLbWpa3 dfz2y28zgVTBXmZnWOiKE0vXyO7ApWyvbdsdRJVDV&e=0&downloadAs=FreeFileViewerSetup.exe&fallback_url=http://www.freefileviewer.com/.../newest.exe

Latest 30 of 222 download URLs

Remove freefileviewersetup.exe - Powered by Reason Core Security