Setup.exe

Application Software Program

OOO Next Stars Group

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The file Setup.exe, “Application Software Program Setup ” by OOO Next Stars Group has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Software Generic   (signed by OOO Next Stars Group)

Product:
Application Software Program

Description:
Application Software Program Setup

MD5:
2a8824cc76612847fea8a12f983de769

SHA-1:
12f66d6df229cbd4bae84864e594224954e73e17

SHA-256:
38777422b624830cf5d7791d9958f5bbd0c1d7c96698ec6b051a94582e0f4789

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2024 10:32:47 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Sality.AT
7.11.30.172

avast!
Trojan-gen
2014.9-150427

ESET NOD32
Win32/InstallCore.ZC potentially unwanted (variant)
9.11540

Reason Heuristics
PUP.Installer.OOONextStarsGroup
15.5.3.0

VIPRE Antivirus
Threat.4150696
39486

File size:
807.4 KB (826,776 bytes)

Product version:
4.1.4

Copyright:
Internet

Bundler/Installer:
installCore (using Inno Setup)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/19/2015 6:00:00 PM

Valid to:
1/20/2016 5:59:59 PM

Subject:
CN=OOO Next Stars Group, OU=OOO Next Stars Group - Development, O=OOO Next Stars Group, STREET=SPIRIDONOVKA 17 STR.11, L=Moscow, S=Moscow, PostalCode=123001, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
69D3B792A60A05CF691C3D5B51AE05EC

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:TqS1JOHtq+VRNIrkTQttZ6mL6OLvxhwa92ril:T31sdbNg1PFhOril

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.8199

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

Remove Setup.exe - Powered by Reason Core Security