setup positioningdrivesv2.0.12.exe

PositioningDrives

Festo AG & Co. KG

The application setup positioningdrivesv2.0.12.exe, “PositioningDrives Setup ” by Festo AG & Co. KG has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.festo.com.
Publisher:
Festo AG & Co.KG   (signed by Festo AG & Co. KG)

Product:
PositioningDrives

Description:
PositioningDrives Setup

MD5:
03f37f6bcf889411c7ab9e3db9f3cca9

SHA-1:
70f8aa022dc3d99fd9c6da3d42b31ea1665b23b6

SHA-256:
37a5042fafe6d87c1e0174c3b773989592c8a7c63e0fa7ed2139fb13c54275a5

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/14/2024 6:01:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.IM (L)
17.1.22.12

File size:
9.8 MB (10,269,672 bytes)

Product version:
V2.0.12

Copyright:
Copyright © 2006-2012 Festo AG & Co.KG

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\setup positioningdrivesv2.0.12.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/28/2010 2:00:00 AM

Valid to:
10/28/2013 12:59:59 AM

Subject:
CN=Festo AG & Co. KG, OU=Festo, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Festo AG & Co. KG, L=Esslingen, S=Baden Wuerttemberg, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6921D10B3E180913C638663A490027DC

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, E8, CD, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E8, CD...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file setup positioningdrivesv2.0.12.exe has been seen being distributed by the following URL.

http://www.festo.com/net/SupportPortal/Files/.../Setup PositioningDrivesV2.0.12.exe

Remove setup positioningdrivesv2.0.12.exe - Powered by Reason Core Security