setup.exe

Bundlore LTD

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe, “Any Media Converter setup” by Bundlore has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. The file has been seen being downloaded from deb.freevideodownloadsonline.com and multiple other hosts.
Publisher:
Any Media Converter  (signed by Bundlore LTD)

Product:
Any Media Converter

Description:
Any Media Converter setup

Version:
1.14

MD5:
c9ec6dee189088160278ca59ab2e79cd

SHA-1:
28755433de6216f850a00f18866c50c958110e57

SHA-256:
d31d15a9be1f0f0bbdbe0c310d3e4cb7a721954014712c16ad0e161682753cd0

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/26/2024 8:36:15 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
AdInstaller.Bundlor
2017.0.2863

Dr.Web
Adware.Downware.514
9.0.1.016

ESET NOD32
Win32/Toolbar.Conduit
10.11056

G Data
Win32.Adware.Conduit
16.1.24

IKARUS anti.virus
PUA.Bundlore
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.191.14720

Norman
Bundlore.CERT
11.20160116

Panda Antivirus
PUP/Conduit.A
16.01.16.01

Reason Heuristics
PUP.Bundlore.AnyMediaConverter.Bundler (M)
16.1.16.1

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Wajam
36876

File size:
597 KB (611,296 bytes)

Copyright:
© Any Media Converter (Converter_I134_AUTO_NICE_SIGNED_WITHPOST)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/5/2012 2:00:00 AM

Valid to:
7/6/2014 1:59:59 AM

Subject:
CN=Bundlore LTD, O=Bundlore LTD, STREET=Beit Oved 9, L=Tel Aviv, S=Israel, PostalCode=67211, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0C7A8094C56AAFE39F3CA37C7F65AC84

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:XkyeFXjzA6X7C2jG5kL7X0IzKzuLae4ZTGvAA61bhxQOODZ:Xkfr7CYG23LIu74OQ1b

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security