setup.exe

Chromium

Limited Liability Company Ucoz Media

The application setup.exe by Limited Liability Company Ucoz Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program Uran by Uran.
Publisher:
The Chromium Authors  (signed by Limited Liability Company Ucoz Media)

Product:
Chromium

Version:
22.0.1229.79

MD5:
2cf8adafee6060b0e37314c8cd4cba0f

SHA-1:
01f899453f1ac001bb66cc2161988a84c03aea35

SHA-256:
745d9e3953b42c9951b472c0e6ca49d884682ba0255e49835703244fdd716764

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 3:52:00 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.LimitedLiabilityCompanyUcozMedia.Installer (M)
16.2.23.14

File size:
1.6 MB (1,650,136 bytes)

Product version:
22.0.1229.79

Copyright:
Copyright (C) 2006-2010 The Chromium Authors. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\uran\application\22.0.1229.79\installer\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/16/2012 10:17:49 PM

Valid to:
3/17/2014 10:17:49 PM

Subject:
E=alexzander@ucoz.com, CN=Limited Liability Company Ucoz Media, OU=Bagrationovskiy proyezd, O=Limited Liability Company Ucoz Media, L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B28BB43AF25490AA12229BA614435817

File PE Metadata
Compilation timestamp:
10/2/2012 5:36:55 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:lnyMYmiH692trRMApK8iu88Ozw5vlaaqw1gyq+2crdJ4POOlylt:JylmgBta8ONwWtw1Y+vrdJ+xot

Entry address:
0xBF56D

Entry point:
E8, 57, B1, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 13, 87, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, B8, 97, 52, 00, 74, 12, 8B, 0D, 70, 95, 52, 00, 85, 48, 70, 75, 07, E8, C2, 84, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 68, 9C, 52, 00, 74, 16, 8B, 46, 08, 8B, 0D, 70, 95, 52, 00, 85, 48, 70, 75, 08, E8, B0, B3, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A...
 
[+]

Code size:
879 KB (900,096 bytes)

Program Uninstaller
Program name:
Uran

Display publisher:
Uran

Display version:
22.0.1229.79

Uninstall string:
"C:\users\{user}\appdata\local\uran\application\22.0.1229.79\installer\setup.exe" --uninstall --verbose-logging


Remove setup.exe - Powered by Reason Core Security