Setup.exe

File

saFe insTall OpT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file Setup.exe by saFe insTall OpT has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
saFe insTall OpT  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
62b713c1c99180233b9e48b3857663a9

SHA-1:
13fa79d0a64de3efd26dec42d30e2f1e88743c8f

SHA-256:
33b423987f63529e2c36dbed3c43d1ae424ece666a95f8be62e8096a2b09e501

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/24/2024 6:50:34 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.28

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
Malware-gen
150320-0

AVG
Downloader
2016.0.3158

Dr.Web
infected with Trojan.OutBrowse.225
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted
9.11386

G Data
NSIS.Application.OutBrowse.AC
15.3.25

McAfee
Artemis!C642B341E69C
5600.6814

Reason Heuristics
Threat.saFeinsTallOpT
15.4.11.23

Sophos
Generic PUA LC
4.98

Trend Micro House Call
Suspici.692BA229
7.2.86

VIPRE Antivirus
Threat.4150696
38552

File size:
1 MB (1,100,944 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar27-072447-54db5450-17ee-42d9-9fcc-ed5f6944e51c.exe

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/23/2015 12:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=saFe insTall OpT, O=saFe insTall OpT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2D154EC2D5B2A57A0C1599905D1CC29D

File PE Metadata
Compilation timestamp:
3/27/2015 7:24:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:nbSaE4mvt/bCdu/TgGrc1zGHxcjZwJP3:nbSv4mv1eJmmqRcjZ

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5478

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove Setup.exe - Powered by Reason Core Security