Setup.exe

Windows Media Player Folder Sharing Executable

Strong Media

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The file Setup.exe, “Windows Media Player Folder Sharing Executable” has been detected as malware by 1 anti-virus scanner. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Microsoft Corporation  (signed by Strong Media)

Product:
Microsoft® Windows® Operating System

Description:
Windows Media Player Folder Sharing Executable

Version:
11.0.5721.5262 (WMP_11.090130-1421)

MD5:
5a676a7e81a2e31609f15a0cc6c5941f

SHA-1:
0881d2bcc28d5a327d260df33f64c411bbd59345

SHA-256:
c0e48dc2cdc1819475b35e351aebf88058469e36d2476ff33f36e609e391307f

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/29/2024 8:10:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.2.10

File size:
914 KB (935,912 bytes)

Product version:
11.0.5721.5262

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
wmpshare.exe

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/13/2016 5:00:00 PM

Valid to:
6/14/2017 4:59:59 PM

Subject:
CN=Strong Media, O=Strong Media, STREET="Sokolniki Square, 4 A", L=Moscow, S=Moscow, PostalCode=107113, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DE80B6BBB2E40F5F7B3C2F4B76F141D9

File PE Metadata
Compilation timestamp:
7/14/2016 5:14:19 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1030

Entry point:
55, 8B, EC, 81, EC, 20, 04, 00, 00, 68, 4C, 20, 4D, 00, FF, 15, 0C, 70, 4B, 00, 8B, 45, EC, 69, C0, 56, A0, EC, 11, 89, 45, F8, 68, 54, 20, 4D, 00, FF, 15, 98, 70, 4B, 00, 8B, 55, F8, 8B, 4D, EC, D3, E2, 89, 55, F8, 8B, 45, A4, 2B, 45, AC, 89, 45, AC, 8B, 55, 90, 8B, 4D, AC, D3, E2, 89, 55, B4, 8B, 45, 9C, C1, E0, 75, 89, 45, 98, 8B, 55, 90, 8B, 4D, 88, D3, EA, 89, 55, 8C, 8B, 45, A8, 69, C0, FF, 92, 4C, 0A, 89, 45, A8, FF, 15, 28, 71, 4B, 00, C6, 85, D4, FE, FF, FF, EA, 8B, D2, 8B, 55, 08, 8B, D2, 89, 15...
 
[+]

Entropy:
6.3477

Developed / compiled with:
Microsoft Visual C++

Code size:
725.5 KB (742,912 bytes)

Remove Setup.exe - Powered by Reason Core Security