setup.exe

Polyanskaya Irina

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application setup.exe by Polyanskaya Irina has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Polyanskaya Irina  (signed and verified)

MD5:
f4bc160fffc216c18acc922974c9647f

SHA-1:
ad44b82e3df2374045244fb71e0d1985dd9684c0

SHA-256:
0389f019290ad9fe73c11a11b9a72254064d1fc5d98d24049cf410ff2bd24107

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 1:53:05 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
16.8.21.6

File size:
2.3 MB (2,373,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/24/2014 8:00:00 PM

Valid to:
8/25/2015 7:59:59 PM

Subject:
CN=Polyanskaya Irina, O=Polyanskaya Irina, STREET="Suhata Reka, Bl. 225A, Ap. 42", L=Sofia, S=Sofia, PostalCode=1517, C=BG

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A4C6F876119E08B1C5FF63372D64B83F

File PE Metadata
Compilation timestamp:
11/25/2014 5:29:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:82pID5N+Th0JnvOI3eJ8f5OuHWaGF+26Mj9LQ6FddHS4i06rLNQM+xXnWu3H:8RGTh0JnvneJ8f5vHWaGF+26U9LhJS4f

Entry address:
0xF7F85

Entry point:
E8, 9E, 85, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, 70, C5, 56, 00, 75, 02, F3, C3, E9, 25, 86, 00, 00, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 22, 82, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, D0, CE, 56, 00, 74, 12, 8B, 0D, 88, CC, 56, 00, 85, 48, 70, 75, 07, E8, 8F, 90, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 90, CB, 56, 00, 74, 16, 8B, 46, 08, 8B, 0D, 88, CC, 56, 00, 85, 48, 70, 75, 08, E8, EE, 88, 00, 00, 89, 46, 04, 8B, 46, 08, F6...
 
[+]

Entropy:
7.0596

Code size:
1.1 MB (1,181,696 bytes)

Remove setup.exe - Powered by Reason Core Security