fyzip-setup.exe

Download Admin

This is the Tightrope WebInstall which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application fyzip-setup.exe by Download Admin has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the Tightrope WebInstall installer.
Publisher:
Download Admin  (signed and verified)

MD5:
bac24f82681d0901431f44d37c7a8340

SHA-1:
8e81c07c29d2fe4ac4a4747ab24f1110493917b5

SHA-256:
80c4292fc1d2f04e63c5ea9dd5d064b2aa19e40f4471822473992a82f4017c85

Scanner detections:
6 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/28/2024 11:10:49 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.538
9.0.1.05190

ESET NOD32
Win32/DownloadAdmin.G potentially unwanted application
7.0.302.0

NANO AntiVirus
Riskware.Win32.Downware.crgjbr
0.28.0.59921

Reason Heuristics
PUP.Installer.DownloadAdmin.L
14.8.7.20

Sophos
Download Admin
4.98

VIPRE Antivirus
Threat.4783369
29418

File size:
715.7 KB (732,840 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Tightrope WebInstall (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\fyzip-setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/2/2010 7:00:00 PM

Valid to:
5/29/2013 6:59:59 PM

Subject:
CN=Download Admin, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Download Admin, L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
29529B0D185F8525A92A866D4A38DA3A

File PE Metadata
Compilation timestamp:
6/22/2012 1:07:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:LxpJADKNY1uSpYvD3q/I6AFd6UQCBXtf4p/UJaJgpk:Fp2DKa1uSm2A6ud6XCTcwaEk

Entry address:
0x333B

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, B0, 73, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, C0, 70, 40, 00, 53, FF, 15, 88, 72, 40, 00, 6A, 08, A3, B8, 3C, 42, 00, E8, 2C, 25, 00, 00, 53, 68, 60, 01, 00, 00, A3, C0, 3B, 42, 00, 8D, 44, 24, 38, 50, 53, 68, 43, 74, 40, 00, FF, 15, 64, 71, 40, 00, 68, 38, 74, 40, 00, 68, C0, 33, 42, 00, E8, 1D, 24, 00, 00, FF, 15, BC, 70, 40, 00, 50, BF, 00, 90, 42, 00, 57, E8, 0B, 24, 00, 00...
 
[+]

Entropy:
7.3796

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove fyzip-setup.exe - Powered by Reason Core Security