Setup.exe

UKRREMBUDSERVIS LTD

This is a component of the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by UKRREMBUDSERVIS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
UKRREMBUDSERVIS LTD  (signed and verified)

MD5:
02f032212a39cbd1546e898be296bd1e

SHA-1:
2509d6b463c217175a95e030bacc3caacd2f5860

SHA-256:
8a6300786e1c4cc8342948129893780cedd3dfd85e9b665fc37124438274e9d8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 6:53:42 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Bundlore (M)
17.3.14.6

File size:
351.5 KB (359,944 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/22/2015 8:00:00 PM

Valid to:
3/22/2016 7:59:59 PM

Subject:
CN="""UKRREMBUDSERVIS"" LTD", O="""UKRREMBUDSERVIS"" LTD", STREET="Stepana Sahaydaka str, 100-A", L=Kiev, S=Kiev, PostalCode=02002, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2275F2D622D08DDBED9ABADB3884FAA5

File PE Metadata
Compilation timestamp:
5/11/2015 11:43:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x657D

Entry point:
E8, 36, 65, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 38, A4, 42, 00, E8, 5D, 48, 00, 00, E8, 07, 67, 00, 00, 0F, B7, F0, 6A, 02, E8, C9, 64, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, B6, 38, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.9980

Code size:
131 KB (134,144 bytes)

Remove Setup.exe - Powered by Reason Core Security