nexgen setup.exe

Ignition Installer

This is the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application nexgen setup.exe by Ignition Installer has been detected as adware by 5 anti-malware scanners. The program is a setup application that uses the Verti Setup installer. The file has been seen being downloaded from moozymp3.com and multiple other hosts.
Publisher:
Ignition Installer  (signed and verified)

MD5:
23237e889a02a1203e711166a181c85c

SHA-1:
4053b90dbc12acf4edd661d7438ea9172be2a443

SHA-256:
a4b66a8bfe82cc5ed31677c1c7a3039e3f437d9b2d875d15680672b8a8d24d68

Scanner detections:
5 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/2/2024 5:31:40 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Skodna.Generic_c
2014.0.3613

Malwarebytes
PUP.Optional.Ignition.A
v2013.12.26.11

Reason Heuristics
PUP.Installer.IgnitionInstaller.M
14.8.8.0

Trend Micro House Call
TROJ_GEN.F47V0920
7.2.360

VIPRE Antivirus
Ignition Installer
24162

File size:
224.8 KB (230,144 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Verti Setup

Common path:
C:\users\{user}\downloads\nexgen setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/12/2013 1:00:00 AM

Valid to:
2/9/2014 12:59:59 AM

Subject:
CN=Ignition Installer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Ignition Installer, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1FD055D1404C62D90F067E086F0FADAE

File PE Metadata
Compilation timestamp:
7/14/2013 10:10:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:pFaym9jH9Wd6Zr13TZ7zJfOwhF54LiYewW0A5M1:Nm9p1Zv7scz4L3DCM1

Entry address:
0x30DC

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 78, 6F, 44, 00, E8, 73, 2D, 00, 00, A3, C4, 6E, 44, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 80, 9C, 42, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, 2E, 44, 00, E8, 1D, 2A, 00, 00, FF, 15, 1C, 71, 40, 00, BD, 00, F0, 46, 00, 50, 55, E8, 0B, 2A...
 
[+]

Code size:
23 KB (23,552 bytes)

The file nexgen setup.exe has been seen being distributed by the following 2 URLs.

Remove nexgen setup.exe - Powered by Reason Core Security