setup.exe

Prog Internet

Software program

The application setup.exe, “Prog Internet Setup ” has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from cdn.downloaddart.com and multiple other hosts.
Publisher:
Software program

Product:
Prog Internet

Description:
Prog Internet Setup

Version:
5.3.2.7

MD5:
be19d45daf62e8457b0d722c14f68e36

SHA-1:
178dd4b3a1dd1d80f64d58a9a6dba5fbbfa8071f

SHA-256:
a609f8298eba7a6a258a870da08987476bf0abe2348da361750949e1a9de594c

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 6:32:22 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/InstallCore.ACZ potentially unwanted (variant)
9.12351

Fortinet FortiGate
Riskware/InstallCore
11/9/2015

K7 AntiVirus
Adware
13.210.17417

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.1148

Qihoo 360 Security
HEUR/QVM42.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.InstallCore.Bundler (M)
15.11.9.10

File size:
508.3 KB (520,495 bytes)

Product version:
2.5

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:CcxGuYpmiJku3ozpK0NTVqL+MBTlPadSfXioRcpMXVJoT:CcxnYpVJkg67NT4CMBTlP0QjcpMXVJoT

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9266

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

http://cdn.downloaddart.com/.../setup.exe

Remove setup.exe - Powered by Reason Core Security