itunes_setup.exe

Start Playing

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application itunes_setup.exe by Start Playing has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. With this installer, users are expecting to download Apple's iTunes but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Start Playing  (signed and verified)

MD5:
fe2a731a4c37d889d2a4ba3714be8482

SHA-1:
f598320aa962bfa56ed7fb3dd6d0ddcf01bcb13d

SHA-256:
235fe51c95bd3fc564bd5acef8904c59796c031bca6d7fe9a415ad925549339e

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 8:46:19 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2014.12.29

Avira AntiVirus
APPL/Outbrowse.Gen
7.11.198.100

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.OutBrowse
v2014.12.28.02

McAfee
Program.Adware-OutBrowse.c
16.8.708.2

Reason Heuristics
PUP.Installer.StartPlaying.M
14.12.28.13

Trend Micro House Call
Suspici.8B120837
7.2.362

File size:
566.5 KB (580,088 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\itunes_setup.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
12/8/2014 6:12:48 AM

Valid to:
12/8/2015 6:12:48 AM

Subject:
CN=Start Playing, O=Start Playing, L=DUBLIN, C=IE

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4E956215A6BB61

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:pe34tJZ2/OtFZ2n9fiZu/cisiTFlW6OCOrrH5y/OnvyrGA/Pq/Zq2mQXj1Mej+DD:9Jgrn9cUjPTFdOCYr8Fd6o5eqQ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9729

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file itunes_setup.exe has been seen being distributed by the following URL.

Remove itunes_setup.exe - Powered by Reason Core Security