setup.exe

FUSION INSTALLER

This adware bundler is distributed through Adknowledge's advertising supported software managers. The application setup.exe, “Fusion Install ” by FUSION INSTALLER has been detected as adware by 37 anti-malware scanners. The program is a setup application that uses the Adknowledge Fusion installer.
Publisher:
Fusion Install   (signed by FUSION INSTALLER)

Product:
Fusion Install

Description:
Fusion Install

Version:
2.4.8.1

MD5:
2a4340fd9fb45e19f15cb308467fa581

SHA-1:
802ea0589993b8cb38ad5874ce51b71d5f9ccd9e

SHA-256:
2893a2552b29dde1ad21888006893bd3ca12ded85049f20558db9bb450564232

Scanner detections:
37 / 68

Status:
Adware

Explanation:
This installer bundles various adware prorgams that may include toolbars and web browser advertising injectors/extensions.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/28/2024 4:53:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.IBryte.U
899

Agnitum Outpost
PUA.iBryte
7.1.1

AhnLab V3 Security
PUP/Win32.OptimumInstaller
2014.06.24

Avira AntiVirus
Adware/iBryte.jgr.915
7.11.163.248

avast!
Win32:IBryte-DY [PUP]
140813-1

AVG
Adware AdPlugin.VX
2014.0.3986

Bitdefender
Adware.IBryte.U
1.0.20.1155

Bkav FE
W32.VikesluLTAH.Adware
1.3.0.4959

Clam AntiVirus
Win.Adware.Agent-7183
0.98/19265

Comodo Security
ApplicUnwnt
18969

Dr.Web
Adware.Downware.6099, Adware.iBryte.473
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.iBryte
8.14.08.19.12

ESET NOD32
Win32/AdWare.iBryte.AP application
7.0.302.0

Fortinet FortiGate
W32/Zbot.AAN!tr
8/19/2014

F-Prot
W32/DomaIQ.G2.gen
v6.4.7.1.166

F-Secure
Adware.IBryte.U
11.2014-19-08_3

G Data
14.8.24

IKARUS anti.virus
PUA.PremiumInstaller
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.181.12846

Kaspersky
not-a-virus:AdWare.Win32.iBryte
15.0.0.494

Malwarebytes
PUP.Optional.Optimum
v2014.08.19.12

McAfee
Trojan.Artemis!D06D84983289
5600.7033

MicroWorld eScan
Adware.IBryte.U
15.0.0.693

NANO AntiVirus
Trojan.Win32.Buzus.cywlqp
0.28.0.60475

Norman
Downloader
11.20140819

nProtect
Adware.IBryte.U
14.07.03.01

Panda Antivirus
14.08.19.12

Qihoo 360 Security
Malware.Radar03.Gen
1.0.0.1015

Quick Heal
Adware.iBryte.DK4
8.14.14.00

Reason Heuristics
PUP.Installer.FUSIONINSTALLER.F
14.8.19.12

Rising Antivirus
PE:Malware.iBryte!6.197B
23.00.65.14817

Sophos
Generic PUA KI
4.98

SUPERAntiSpyware
10412

Trend Micro House Call
Suspicious_GEN.F47V0717
7.2.231

Vba32 AntiVirus
3.12.26.3

VIPRE Antivirus
Optimum Installer
31600

Zillya! Antivirus
Adware.iBryte.Win32.923
2.0.0.1835

File size:
315.3 KB (322,856 bytes)

Product version:
2.4.8.1

Copyright:
Copyright (C) 2013 Fusion Install

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adknowledge Fusion

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/4/2013 1:00:00 AM

Valid to:
9/21/2014 12:59:59 AM

Subject:
CN=FUSION INSTALLER, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=FUSION INSTALLER, L=Kansas City, S=Missouri, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
21DB9738D9B500E3DAF0570B5DA9E8B9

File PE Metadata
Compilation timestamp:
7/18/2014 10:28:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:2riNkJdFZiYiBZNENLrgo2SLhp+bTVU4al63op97:2XL6NENLrtvh2gp97

Entry address:
0x181F5

Entry point:
E8, C2, 8D, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 24, D4, 43, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 84, D0, 43, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63...
 
[+]

Entropy:
6.3879

Code size:
238 KB (243,712 bytes)

Remove setup.exe - Powered by Reason Core Security