setup.exe

ProductName

PR Agentstvo IT PRO, TOV

The application setup.exe by PR Agentstvo IT PRO, TOV has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The setup program bundles adware offers using the Amonetize, a Pay-Per-Install (PPI) monetization and distribution download manager. The software offerings provided are based on the PC's geo-location at the time of install.
Publisher:
CompanyName  (signed by PR Agentstvo IT PRO, TOV)

Product:
ProductName

Description:
FileDescription

Version:
4.1.2.1

MD5:
69a9030dcb20b002da523a64a45dea94

SHA-1:
7db6416a9eaac5072b05b80e9cd084bda8a64b67

SHA-256:
a478cd099e6b828d2acd0226202b2a79b6201493c7668ea1453d46e739b2be4a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/23/2024 2:55:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonetize (M)
17.3.16.10

File size:
5.5 MB (5,778,640 bytes)

Product version:
1.3.3.1

Copyright:
LegalCopyright

Trademarks:
LegalTrademarks

Original file name:
OriginalFilename

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
2/27/2017 3:00:00 AM

Valid to:
4/5/2017 2:59:59 AM

Subject:
CN="PR Agentstvo IT PRO, TOV", OU=IT, O="PR Agentstvo IT PRO, TOV", STREET="prosp. 40-Richchya Zhovtnya, 100/2", L=Kiev, S=Kiev, PostalCode=03127, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
34324C879F58ED79DEE14BE0873DA47C

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x1C71E0

Entry point:
55, 8B, EC, 83, C4, D4, 53, 56, 57, 33, C0, 89, 45, DC, 89, 45, E0, 89, 45, E4, 89, 45, E8, B8, F0, 66, 5C, 00, E8, 1B, 0A, E4, FF, 33, C0, 55, 68, 6B, 76, 5C, 00, 64, FF, 30, 64, 89, 20, E8, 54, BF, E3, FF, A1, 0C, EB, 69, 00, E8, 3A, E9, E3, FF, 8D, 55, E8, E8, CA, 36, E4, FF, 8B, 45, E8, E8, 12, 39, E4, FF, 85, C0, 7E, 3B, 89, 45, EC, C7, 05, 18, 6B, 6A, 00, 01, 00, 00, 00, A1, 18, 6B, 6A, 00, 83, 3C, 85, 10, EB, 69, 00, 00, 74, 14, A1, 18, 6B, 6A, 00, 83, 04, 85, 10, EB, 69, 00, 01, 71, 05, E8, A6, CE...
 
[+]

Entropy:
7.5944

Developed / compiled with:
Microsoft Visual C++

Code size:
1.8 MB (1,861,632 bytes)

Remove setup.exe - Powered by Reason Core Security