Setup.exe

My Online Media Ltd.

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by My Online Media has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
My Online Media Ltd.  (signed and verified)

MD5:
791c25a55272ffed4dcc6ed69f42c0c4

SHA-1:
31413cb6f28f4a6a1e1ab25b8a014cb27b1514b1

SHA-256:
363d47bcaf885895df488ab3e358cf3ebd6076552ef802c9327ee2b3003d42ff

Scanner detections:
25 / 68

Status:
Adware

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/27/2024 7:00:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.186081
5594902

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Bundlore
2015.05.16

Avira AntiVirus
PUA/Bundlore.Gen
8.3.1.6

avast!
Win32:Trojan-gen
150319-1

AVG
Adware BundleApp.KE
2014.0.4311

Bitdefender
Gen:Variant.Adware.Graftor.186081
1.0.20.680

Clam AntiVirus
Win.Trojan.Bundlore-31
0.98/21511

Comodo Security
Application.Win32.Bundlore.SDA
22132

Dr.Web
Adware.Downware.10329
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.186081
10.0.0.5366

ESET NOD32
Win32/Bundlore.S potentially unwanted application
7.0.302.0

F-Prot
W32/S-46bf7bb6
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Graftor
11.2015-16-05_7

G Data
Gen:Variant.Adware.Graftor.186081
15.5.25

IKARUS anti.virus
PUA.Bundlore
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.203.15929

Malwarebytes
PUP.Optional.Bundlore.C
v2015.05.16.12

McAfee
Program.PUP-FOZ
17.6.569.0

MicroWorld eScan
Gen:Variant.Adware.Graftor.186081
16.0.0.408

NANO AntiVirus
Trojan.Win32.Bundlore.dqaqzi
0.30.24.1357

Panda Antivirus
Trj/Genetic.gen
15.05.16.12

Reason Heuristics
Threat.Bundlore.Bundler
15.5.15.20

Sophos
PUA 'Bundlore'
5.14

VIPRE Antivirus
Threat.4150696
39486

File size:
284.3 KB (291,144 bytes)

Bundler/Installer:
Bundlore Downloader

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
2/17/2015 7:00:00 PM

Valid to:
2/18/2016 6:59:59 PM

Subject:
CN=My Online Media Ltd., O=My Online Media Ltd., L=Tel Aviv, S=Israel, C=IL

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
6AA804F3A58EAF0737163328AC5B0831

File PE Metadata
Compilation timestamp:
2/28/2015 10:40:53 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:5konno7dSzYRVW8MoyFiDA660yO3z0gUNIUJY4pSugteeMC+6EDoBx74PuLEbCoM:1nFYact6wzsSNYNCeoBtguLGF0bN

Entry address:
0x30BA

Entry point:
E8, 8D, 48, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, AD, 41, 00, E8, F0, 2D, 00, 00, E8, 5E, 4A, 00, 00, 0F, B7, F0, 6A, 02, E8, 20, 48, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, DF, 3F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.0286

Code size:
77 KB (78,848 bytes)

Remove Setup.exe - Powered by Reason Core Security