setup.exe

Conversionads

The application setup.exe by Conversionads has been detected as adware by 10 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from moozymp3.com.
Publisher:
Conversionads  (signed and verified)

MD5:
c3decda1ccadaa5f8d6717c1c4a07946

SHA-1:
a7dbb19388a2cf40c3aeb34c256c61c70916462b

SHA-256:
3ee144acd0b5478b7c61017395ee0ca8db2286acaea4adce200c68ccdf258e42

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/23/2024 9:21:27 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.InstallCore
2014.06.05

Avira AntiVirus
TR/Winwebsec.495616
7.11.153.42

AVG
Agent.F
2016.0.2989

ESET NOD32
Win32/InstallCore.AZ (variant)
9.9893

F-Prot
W32/InstallCore.W.gen
v6.4.7.1.166

Malwarebytes
v2015.09.11.04

Qihoo 360 Security
Win32/Trojan.ea7
1.0.0.1015

Reason Heuristics
PUP.Conversionads.Installer (M)
15.9.11.16

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15909

Sophos
Conversion Ads
4.98

File size:
1.2 MB (1,235,104 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/30/2012 1:00:00 AM

Valid to:
5/31/2013 12:59:59 AM

Subject:
CN=Conversionads, O=Conversionads, STREET=Am Weinberg 5, L=Neubeuern, S=Neubeuern, PostalCode=83115, C=DE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F87F8F45F7BF3EBF80C41AFC59A6916A

File PE Metadata
Compilation timestamp:
6/19/1992 11:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:fHxyVmjPLPMbz5cSWgK+MB+L97/BQjhaRneqW7U94:vxywjPLPMuwMEe8TWQu

Entry address:
0xD5A10

Entry point:
55, 8B, EC, 83, C4, F0, B8, 54, 6B, 41, 00, E8, 1F, F8, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7822

Developed / compiled with:
Microsoft Visual C++

Code size:
866 KB (886,784 bytes)

The file setup.exe has been seen being distributed by the following URL.

Remove setup.exe - Powered by Reason Core Security