setup.exe

Western Web Applications, LLC

The software will display additional offers (such as adware) during installation including a browser toolbar/extension as well as advertising injection software (part of the Injekt brand). The application setup.exe by Western Web Applications has been detected as adware by 15 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
Western Web Applications, LLC  (signed and verified)

MD5:
fd409898b5508a7fc14cd3d23e4ece68

SHA-1:
6dd6fcccc3cef27ca24bfbd7221d991e422f165d

SHA-256:
efc4b49e7109fbc9a2d7a06548fa20ca9ac85c1458c1cc9d321f4bac664d5034

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
11/5/2024 6:48:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.143453
433

Bitdefender
Gen:Variant.Adware.Graftor.143453
1.0.20.1660

Dr.Web
Adware.OpenCandy.4
9.0.1.0332

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.143453
8.15.11.28.09

ESET NOD32
MSIL/Adware.PullUpdate
9.9969

F-Secure
Gen:Variant.Adware.Graftor.143453
11.2015-28-11_7

G Data
Gen:Variant.Adware.Graftor.143453
15.11.24

K7 AntiVirus
Trojan
13.180.12463

Malwarebytes
PUP.Optional.OpenCandy
v2015.11.28.09

McAfee
Artemis!BDC607507763
5600.6567

MicroWorld eScan
Gen:Variant.Adware.Graftor.143453
16.0.0.996

NANO AntiVirus
Riskware.Win32.OpenCandy.cxjcyz
0.28.0.60253

Reason Heuristics
PUP.Injekt.WesternWebApplications.Installer (M)
15.11.28.21

Rising Antivirus
PE:PUF.OpenCandy!1.9DE5
23.00.65.151126

VIPRE Antivirus
Injekt
30454

File size:
4.3 MB (4,558,920 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/2/2014 8:00:00 PM

Valid to:
6/3/2015 7:59:59 PM

Subject:
CN="Western Web Applications, LLC", O="Western Web Applications, LLC", L=Del Mar, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2846A7B6FF6C3C84D2AC5AD12B664347

File PE Metadata
Compilation timestamp:
6/6/2009 5:41:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:H0AN57ZCF0bOEfYx90mUscsOwjElcbdQNAzHJ:3zgCaEfYj6sJIcbzzp

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9747

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security