Setup.exe

File

saFe insTall OpT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file Setup.exe by saFe insTall OpT has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
saFe insTall OpT  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
d20d6b2b2433abed7aeaabc88a5c8ee8

SHA-1:
ae2531bcf168c88270a668031c45cb35484b9a3d

SHA-256:
be0102d0473e0f6c562f722de9caf41a1b0cabc5e88106c76dbb23e99a8adaf6

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/24/2024 6:28:06 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.28

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
Malware-gen
150319-0

AVG
Downloader
2016.0.3158

Dr.Web
infected with Trojan.OutBrowse.225
9.0.1.05190

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

G Data
NSIS.Application.OutBrowse.AC
15.3.25

McAfee
Artemis!C642B341E69C
5600.6814

Reason Heuristics
Threat.saFeinsTallOpT
15.4.11.23

Sophos
Generic PUA LC
4.98

Trend Micro House Call
Suspici.692BA229
7.2.86

VIPRE Antivirus
Threat.4150696
38552

File size:
1 MB (1,100,944 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar27-072511-0f5fed5e-1dc3-4a94-b72a-e265afc4e2bd.exe

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/23/2015 12:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=saFe insTall OpT, O=saFe insTall OpT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2D154EC2D5B2A57A0C1599905D1CC29D

File PE Metadata
Compilation timestamp:
3/27/2015 7:25:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:bbSaE4mvt/RzTbhHAOjClLcN/c9DwHP/h:bbSv4mvHPOGo4Vc9D

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5476

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove Setup.exe - Powered by Reason Core Security