setup.exe

The application setup.exe has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from ttb.lpmxp2149.com.
MD5:
b9571c425a2d17b6660146304f39c978

SHA-1:
51f4b0094189e970ce879b2f0504058aa5da10af

SHA-256:
c333ca7d5b0789a21dfc5d623036b43638ed87a3711ea0f8cf43ac961fcc05ab

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
12/25/2024 1:54:20 PM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
Application.Bundler.DomaIQ.T
10.0.0.5366

Kaspersky
Trojan.Win32.Buzus
15.0.0.562

Norman
Application.Bundler.DomaIQ.T
03.12.2014 13:20:04

File size:
165.7 KB (169,706 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
9/4/2014 4:32:09 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:rYWyhyAXttbEI5+ve6R5bOvbjZf732carT1CkPuvmbgeCdF:c9hy8tlzp6R5bOvb9m5PuvXdF

Entry address:
0x5A07

Entry point:
E8, 41, 2A, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 04, F7, C1, 03, 00, 00, 00, 74, 24, 8A, 01, 83, C1, 01, 84, C0, 74, 4E, F7, C1, 03, 00, 00, 00, 75, EF, 05, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8D, A4, 24, 00, 00, 00, 00, 8B, 01, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C1, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 41, FC, 84, C0, 74, 32, 84, E4, 74, 24, A9, 00, 00, FF, 00, 74, 13, A9, 00, 00, 00, FF, 74, 02, EB, CD, 8D, 41, FF, 8B...
 
[+]

Code size:
60 KB (61,440 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security