Setup.exe

UKRREMBUDSERVIS LTD

This is a component of the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by UKRREMBUDSERVIS has been detected as adware by 23 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
UKRREMBUDSERVIS LTD  (signed and verified)

MD5:
836df723a24ec2eb8ed5272538d2d3fd

SHA-1:
56203195c6727887e60c8574ff38474bd923d276

SHA-256:
abba40bf02095adbd1d9ecc31f53a81e6e70f9df5d3dc26da573c43b0978627a

Scanner detections:
23 / 68

Status:
Adware

Analysis date:
11/27/2024 8:29:25 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.185745
5544653

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Bundler
2015.05.25

Avira AntiVirus
PUA/Bundlore.Gen
8.3.1.6

avast!
Win32:PUP-gen [PUP]
150521-0

AVG
Generic
2016.0.3099

Bitdefender
Gen:Variant.Graftor.185745
1.0.20.720

Dr.Web
Adware.Downware.9625
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Graftor.185745
10.0.0.5366

ESET NOD32
Win32/Bundlore.T potentially unwanted application
7.0.302.0

F-Prot
W32/S-b5ba81db
v6.4.7.1.166

F-Secure
Gen:Variant.Graftor.185745
5.14.151

G Data
Gen:Variant.Graftor.185745
15.5.25

IKARUS anti.virus
PUA.Bundlore
t3scan.1.8.9.0

K7 AntiVirus
Unwanted-Program
13.204.16012

McAfee
Program.PUP-FOZ
17.6.569.0

MicroWorld eScan
Gen:Variant.Graftor.185745
16.0.0.432

NANO AntiVirus
Riskware.Win32.Downware.dqttqr
0.30.24.1636

Panda Antivirus
Trj/Genetic.gen
15.05.24.05

Reason Heuristics
PUP.Bundlore.UKRREMBUDSERVIS
15.5.24.16

Sophos
PUA 'Bundlore'
5.14

VIPRE Antivirus
Threat.4150696
40432

Zillya! Antivirus
Backdoor.PePatch.Win32.71536
2.0.0.2188

File size:
359.5 KB (368,136 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/22/2015 7:00:00 PM

Valid to:
3/22/2016 6:59:59 PM

Subject:
CN="""UKRREMBUDSERVIS"" LTD", O="""UKRREMBUDSERVIS"" LTD", STREET="Stepana Sahaydaka str, 100-A", L=Kiev, S=Kiev, PostalCode=02002, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2275F2D622D08DDBED9ABADB3884FAA5

File PE Metadata
Compilation timestamp:
4/22/2015 3:27:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:AzQTS8h7PMcLxEH2uBDhvgeVGu2DqYpf5zVvQV2FwsuSlEh8y:n9DMc1EH2uhhvgUAqYpf5zVvQV2Fiyy

Entry address:
0x7A8D

Entry point:
E8, 66, 5B, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, CF, 42, 00, E8, 9D, 48, 00, 00, E8, 37, 5D, 00, 00, 0F, B7, F0, 6A, 02, E8, F9, 5A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 62, 43, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.9889

Code size:
141 KB (144,384 bytes)

Remove Setup.exe - Powered by Reason Core Security