setup.exe

Small Island Development

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Small Island Development has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from gp387a.sazzip.com.
Publisher:
Small Island Development  (signed and verified)

MD5:
9920bad6900893686c44ff281b7ddd95

SHA-1:
2dfbe9c3a697a677afec01e8cd8b4e20222b26da

SHA-256:
4ec98cb124f8a8f9f513a21a3f6786a08b4a3141838e705b702fc5680be8878e

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/27/2024 2:27:22 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.TVWizard
2015.02.25

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.212.104

AVG
Generic_r
2016.0.3187

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.15225

Dr.Web
Adware.Yontoo.57
9.0.1.056

ESET NOD32
MSIL/Adware.PullUpdate
9.11229

K7 AntiVirus
Adware
13.198.15073

Kaspersky
not-a-virus:AdWare.MSIL.PullUpdate
14.0.0.2431

Malwarebytes
PUP.Optional.TVWizard.A
v2015.02.25.05

NANO AntiVirus
Riskware.Win32.PullUpdate.dmgkwr
0.30.0.296

Reason Heuristics
PUP.Installer.Injekt
15.2.25.17

Trend Micro House Call
TROJ_GEN.R0C1B01BP15
7.2.56

Vba32 AntiVirus
AdWare.MSIL.PullUpdate
3.12.26.3

VIPRE Antivirus
Injekt
37880

File size:
4.5 MB (4,674,680 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/24/2014 10:30:00 AM

Valid to:
2/23/2016 10:29:59 AM

Subject:
CN=Small Island Development, O=Small Island Development, L=St. James, S=St. James, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2ACB4CDCE993E485342ABFA2BCA95A17

File PE Metadata
Compilation timestamp:
6/7/2009 7:11:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:aZBpUr0UO8WZSjyB4iMLnbNAIQ51YPONWyIGPDErstfxASeoIYm9bBwar0UO8WZK:aZvUrpO8WwA5ioKPONtIGPHuzBwarpOq

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9826

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security