Setup.exe

AC BUISNESSEXPERTAUDIT LLC

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by AC BUISNESSEXPERTAUDIT has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
AC BUISNESSEXPERTAUDIT LLC  (signed and verified)

MD5:
275b1ed5f43c7a1a37d7bc2995601763

SHA-1:
a7b39aba514bb3794f18c3ea9a0b844f1171fd19

SHA-256:
a6ae2c1e0ed7c96789c72fbae662b150df68fec0b56e4c83d00b9504d83fbf24

Scanner detections:
22 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/26/2024 2:40:32 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.181023
5633907

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Bundlore
2015.04.15

Avira AntiVirus
PUA/Bundlore.Gen
3.6.1.96

avast!
Win32:Malware-gen
150319-1

AVG
Adware BundleApp.JU
2014.0.4311

Bitdefender
Gen:Variant.Graftor.181023
1.0.20.525

Clam AntiVirus
Win.Trojan.Agent-861418
0.98/21511

Comodo Security
Application.Win32.Bundlore.SDA
21770

Emsisoft Anti-Malware
Gen:Variant.Graftor.181023
9.0.0.4799

ESET NOD32
Win32/Bundlore.S potentially unwanted application
7.0.302.0

F-Prot
W32/S-85cc3c59
v6.4.7.1.166

F-Secure
Gen:Variant.Graftor.181023
5.13.68

G Data
Gen:Variant.Graftor.181023
15.4.25

IKARUS anti.virus
PUA.Bundlore
t3scan.1.8.9.0

Malwarebytes
PUP.Optional.Bundlore.C
v2015.04.15.04

MicroWorld eScan
Gen:Variant.Graftor.181023
16.0.0.315

NANO AntiVirus
Trojan.Win32.Bundlore.dpulrs
0.30.16.1110

Panda Antivirus
Trj/Genetic.gen
15.04.15.04

Reason Heuristics
Threat.Bundlore.Bundler
15.4.14.21

VIPRE Antivirus
Threat.4150696
38950

File size:
284.5 KB (291,344 bytes)

Bundler/Installer:
Bundlore Downloader

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/5/2015 6:00:00 PM

Valid to:
3/5/2016 5:59:59 PM

Subject:
CN=AC BUISNESSEXPERTAUDIT LLC, O=AC BUISNESSEXPERTAUDIT LLC, STREET="Kostolna, budynok 6", L=Kyyiv, S=Kyyivska, PostalCode=01001, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
392FC45328E9B4C2D05A6572147A234C

File PE Metadata
Compilation timestamp:
3/8/2015 11:12:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:FqHeI7cX/lSWKHNp7BIkF2JVmZv/WrTgjDF31ln:4z7c0HnqkFKVmkgjDF3Ln

Entry address:
0x30AA

Entry point:
E8, 8D, 48, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 48, AD, 41, 00, E8, F0, 2D, 00, 00, E8, 5E, 4A, 00, 00, 0F, B7, F0, 6A, 02, E8, 20, 48, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, DF, 3F, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.0223

Code size:
77 KB (78,848 bytes)

Remove Setup.exe - Powered by Reason Core Security