itunes_setup.exe

INSTALL DOT EXE

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application itunes_setup.exe, “Premium Installer ” by INSTALL DOT EXE has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Adknowledge Fusion installer. The installer is marketed through download protals and search ads as Apple's iTunes but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Premium Installer   (signed by INSTALL DOT EXE)

Product:
Premium Installer

Description:
Premium Installer

Version:
2.4.8.1

MD5:
8f5dca6ca36624fbe66fe5369e9ed282

SHA-1:
3cfb6b2b51f67161fda02583fcb69c4cae042163

SHA-256:
18d681420b13c806f33d810abb7083b764b37ca23b71704ccbf58112522bfc1d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 3:51:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Adknowledge.INSTALLD.Installer (M)
16.7.1.18

File size:
2.1 MB (2,207,528 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Premium Installer

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\itunes_setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/3/2013 6:00:00 PM

Valid to:
9/20/2014 5:59:59 PM

Subject:
CN=INSTALL DOT EXE, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=INSTALL DOT EXE, L=Kansas City, S=Missouri, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4C8303B332693FCF64E1E7DFD7841493

File PE Metadata
Compilation timestamp:
12/25/2013 9:04:25 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:edSLpWKM4NptvjqWuOYnNqEnD8OQ1DGnkT+B+BdH:rWKM4Nptq7D8OQkntBE

Entry address:
0x69E25

Entry point:
E8, 62, 8C, 00, 00, E9, 78, FE, FF, FF, 6A, 0C, 68, 88, 8C, 4A, 00, E8, C1, 35, 00, 00, 83, 65, E4, 00, 8B, 75, 08, 3B, 35, 58, 54, 61, 00, 77, 22, 6A, 04, E8, 65, 8E, 00, 00, 59, 83, 65, FC, 00, 56, E8, C7, 9B, 00, 00, 59, 89, 45, E4, C7, 45, FC, FE, FF, FF, FF, E8, 09, 00, 00, 00, 8B, 45, E4, E8, CD, 35, 00, 00, C3, 6A, 04, E8, 48, 8D, 00, 00, 59, C3, 8B, FF, 55, 8B, EC, 83, 3D, B4, 40, 61, 00, 00, 75, 18, E8, 99, 81, 00, 00, 6A, 1E, E8, C1, 7F, 00, 00, 68, FF, 00, 00, 00, E8, D7, 4C, 00, 00, 59, 59, A1...
 
[+]

Entropy:
7.1996

Code size:
599 KB (613,376 bytes)

The file itunes_setup.exe has been seen being distributed by the following URL.

Remove itunes_setup.exe - Powered by Reason Core Security