irsetup.exe

Setup Factory Runtime

Mindspark Interactive Network

This is the installer stub for the Mindspark (Indigo Rose Corporation/Ask) browser toolbar which provides the offer to the end user to install the toolbar and set the browser's search, home page and new tab to an Ask.com search destination. The application irsetup.exe, “Setup Application” by Mindspark Interactive Network has been detected as a potentially unwanted program by 0 anti-malware scanners. The program is a setup application that uses the Mindspark Custom Setup installer. This is installed with VideoDownloadConverter.
Publisher:
Indigo Rose Corporation  (signed by Mindspark Interactive Network)

Product:
Setup Factory Runtime

Description:
Setup Application

Version:
9.2.0.0

MD5:
093cfd9d50ba2fdee7ad908b1d0371f9

SHA-1:
82b240f0aa4738aa4b8b5aee145b297722c3d660

SHA-256:
5fc6e959ecc6ae986ef9e79b08def34f3d573d604a02720d0be4bb017bbcc085

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
11/16/2024 7:25:41 AM UTC  (today)

File size:
1.3 MB (1,352,032 bytes)

Product version:
9.2.0.0

Copyright:
Runtime Engine Copyright © 2013 Indigo Rose Corporation (www.indigorose.com)

Trademarks:
Setup Factory is a trademark of Indigo Rose Corporation

Original file name:
suf_rt.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Mindspark Custom Setup

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\irsetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/10/2012 2:00:00 AM

Valid to:
5/7/2015 1:59:59 AM

Subject:
CN=Mindspark Interactive Network, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mindspark Interactive Network, L=White Plains, S=NewYork, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
098417F7EA6406EC7B320590E17A65B7

File PE Metadata
Compilation timestamp:
8/27/2013 8:43:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:a3BrELwtW5a1bTFQE+m/OHe72CmAD/XWsQRs9fTSO7OwHmPWce6NsC:QR2X6pymME2HAD/W5Rsleo+PWceaF

Entry address:
0x3C40A0

Entry point:
60, BE, 00, 40, 68, 00, 8D, BE, 00, D0, D7, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
1.3 MB (1,314,816 bytes)

The file irsetup.exe has been discovered within the following program.

VideoDownloadConverter  by Mindspark Interactive Network
Publisher's description - “By downloading the Toolbar, you will be installing a toolbar in your Internet browser (which may include both your active browser and any other compatible Internet browser(s) resident on your computer), and any supported email functions and/or chat functions with one or more of the following features provided by Mindspark Interactive Network, Inc.”
www.mindspark.com
61% remove it
 
Powered by Should I Remove It?