Setup.exe

Trojan Killer

Gridinsoft, LLC

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser. The file has been seen being downloaded from cdn.trojan-killer.com and multiple other hosts.
Publisher:
GridinSoft LLC  (signed by Gridinsoft, LLC)

Product:
Trojan Killer

Description:
GridinSoft Trojan Killer Setup

Version:
2.2.6.0

MD5:
5a7514715888c8d81c07915481277e4a

SHA-1:
0b78b88cffd7314ff9ba32cf6911217fe580f109

SHA-256:
2288f360cfb825fc6fd8049c2b83363e59c2d99c6b481f1a116fada2249423bf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 9:52:13 AM UTC  (today)

File size:
62.3 MB (65,324,536 bytes)

Copyright:
Copyright © 2003-2015, GridinSoft LLC

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/12/2011 3:30:00 AM

Valid to:
1/13/2015 3:29:59 AM

Subject:
CN="Gridinsoft, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Gridinsoft, LLC", L=Kiev, S=Kiev, C=UA

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
065DF919B8A90A37DEB26750CBB3BBD3

File PE Metadata
Compilation timestamp:
12/6/2009 2:20:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1572864:hjNASyZIndyDacI8/Zsi0xN5o4/Yg0kwHmkauxVvIrWfEn:FPyZsOac4Jr0kwGJuxVDfS

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
8.0000

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file Setup.exe has been seen being distributed by the following 3 URLs.

Scan Setup.exe - Powered by Reason Core Security