setup.exe

Coffee and Comfort Apps, LLC

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Coffee and Comfort Apps has been detected as adware by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
Coffee and Comfort Apps, LLC  (signed and verified)

MD5:
555ac620c6fbb053c43cb2d91681f0f9

SHA-1:
45b568b72e2b5f82732b72bbe818f24e433a53bd

SHA-256:
5a04e5c16eccf763860011d6f43d45444ab955dac1a08088070f115f1372021e

Scanner detections:
14 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 1:14:59 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:BHO-AMO [PUP]
2014.9-150124

AVG
OpenCandy
2016.0.3219

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/ExFriendAlert.B potentially unwanted application
7.0.302.0

G Data
Win32.Adware.OpenCandy
15.1.24

IKARUS anti.virus
PUA.ExFriendAlert
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.192.14744

Malwarebytes
PUP.Optional.OpenCandy
v2015.01.24.07

NANO AntiVirus
Trojan.Win32.ExFriendAlert.deiobm
0.30.0.64812

Reason Heuristics
PUP.Installer.Injekt
15.1.24.19

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.15122

Sophos
PUA 'OpenCandy'
5.09

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.3

VIPRE Antivirus
Threat.4784449
36694

File size:
1.9 MB (2,034,160 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2013 8:00:00 PM

Valid to:
5/14/2014 7:59:59 PM

Subject:
CN="Coffee and Comfort Apps, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Coffee and Comfort Apps, LLC", L=Grandville, S=Michigan, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3457DE0E78F5E3AFE35393625F451DC0

File PE Metadata
Compilation timestamp:
6/6/2009 5:41:59 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:KsuZNA1pMo3L6T+q9RT39jL2YfECPQZqpMOkyxVZ1CE4OwpnlrEiXl6:KsiOL6qqPtj7BKqGTcCXdllrEi8

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9479

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security