isetting.exe

Salih DEMIRGAN

This is a setup program which is used to install the application. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘isetting’. The file has been seen being downloaded from www.indirveoyna.com.
Publisher:
Salih DEMIRGAN  (signed and verified)

MD5:
f1606a23bf56f70ae1317cf9ad3d23a5

SHA-1:
ad52ac5e6b8b4955d8dd87d500661e6df8f73ad5

SHA-256:
927ce98d9fe0effe5b8c7242be978e363ea2ea991a03f49806523e83145cfe71

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/27/2024 5:20:31 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Salih
2015.0.3464

File size:
2 MB (2,113,968 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\isetting.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/20/2013 2:00:00 AM

Valid to:
11/21/2014 1:59:59 AM

Subject:
CN=Salih DEMIRGAN, O=Salih DEMIRGAN, STREET=Abdül Aziz Mh. Şirin Hanım Sk. No:19, L=Konya, S=Meram, PostalCode=n-a, C=TR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00D93C4C5A7797EED44FF4F38F7E699B06

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:uzpL6DnQ/+Cg3Evr4+4Y9+GTxz5AfSvNFNc:uSnQ/+D3Evr4O9+KifSvNFNc

Entry address:
0x1914A0

Entry point:
55, 8B, EC, 83, C4, F0, B8, F0, 0E, 59, 00, E8, 30, 5B, E7, FF, A1, C4, 8C, 5A, 00, 8B, 00, E8, 78, 39, ED, FF, 8B, 0D, 10, 8F, 5A, 00, A1, C4, 8C, 5A, 00, 8B, 00, 8B, 15, 68, DA, 58, 00, E8, 78, 39, ED, FF, A1, C4, 8C, 5A, 00, 8B, 00, E8, EC, 39, ED, FF, E8, 53, 31, E7, FF, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.6 MB (1,639,936 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
isetting

Command:
C:\Program Files\isetting.exe


The file isetting.exe has been seen being distributed by the following URL.

Scan isetting.exe - Powered by Reason Core Security