setup.exe

Операционная система Microsoft Windows

LIV Konstrakshn, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable setup.exe, “Исполняемый файл для игры "Солитер"” has been detected as malware by 1 anti-virus scanner. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by LIV Konstrakshn, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Солитер"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
c708594fae6699e0cf4eec6a54ce1e69

SHA-1:
113dbd5fb3652da95e2b96c33592cb1990217a91

SHA-256:
aff8eb9ef904c15cdec4d962c71be01ec45217a131b10b2bad763cddf9774217

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 9:35:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.17.6

File size:
2.3 MB (2,391,232 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
freecell.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.rar\setup\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/17/2016 3:00:00 AM

Valid to:
7/24/2017 2:59:59 AM

Subject:
CN="LIV Konstrakshn, TOV", OU=IT, O="LIV Konstrakshn, TOV", STREET="Vulytsya Kirovogradska, Budynok 38/58", STREET=Ofis 15, L=Kyyiv, S=Kyyiv, PostalCode=03069, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
359EF61F4B8E0D1D893C09DFE3350A18

File PE Metadata
Compilation timestamp:
6/7/2014 11:26:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x437C8

Entry point:
6A, 70, 68, 98, 70, 44, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 0C, 70, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 38, 70, 44, 00, 59, 83, 0D, 20, C7, 80, 00, FF, 83, 0D, 24, C7...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
277 KB (283,648 bytes)

Remove setup.exe - Powered by Reason Core Security