Setup.exe

BeSt instAll TLL

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file Setup.exe by BeSt instAll TLL has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
WDFPO  (signed by BeSt instAll TLL)

Product:
WDFPO

Version:
195.15610.1192.7450

MD5:
2c5d4edd73000d1dd68d62db1f03ba4d

SHA-1:
7fd18d9eebd4ba0e15cd55bf492d10dd1d24dc61

SHA-256:
81982d46eeb3f8be8c0e7a4c666480cac8958646aff734e9301366ec84c052a3

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/24/2024 2:41:23 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.06.14

AVG
Downloader
2016.0.3080

ESET NOD32
Win32/OutBrowse.CE potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
6/13/2015

K7 AntiVirus
Unwanted-Program
13.205.16234

McAfee
Program.Adware-OutBrowse.g
17.6.569.0

Reason Heuristics
PUP.Outbrowse.Bundler
15.6.13.10

File size:
751.4 KB (769,408 bytes)

Product version:
195.15610.1192.7450

Copyright:
WDFPO

Trademarks:
WDFPO

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
6/8/2015 1:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=BeSt instAll TLL, O=BeSt instAll TLL, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
51ABD7079C17C6B033FE6982E1CC7C5F

File PE Metadata
Compilation timestamp:
12/5/2009 10:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:kogsJhgOo1t5hV3YsUEBDb0CaKmGCDcqoDAHD2eiWiWn9SVcGMVtZVe9fc8vy4h:kogsJBo1tiabcIDAj2l/sSaG0EC86

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9836

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove Setup.exe - Powered by Reason Core Security