setup.exe

Internet Explorer

Smart Finekspert, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable setup.exe has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by Smart Finekspert, TOV)

Product:
Internet Explorer

Version:
11.00.9600.16428 (winblue_gdr.131013-1700)

MD5:
041dec666d7b4365bb70b1f084a7107c

SHA-1:
b2555be9f6e7fcda72f698b1a20b4bff7df555aa

SHA-256:
cda77c94d00c6882cf6f8378404b9013d41613b0c03a6d20065f635a0c470e1d

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/15/2024 9:34:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.15.12

File size:
3.4 MB (3,602,456 bytes)

Product version:
11.00.9600.16428

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
IEXPLORE.EXE.MUI

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/10/2016 3:00:00 AM

Valid to:
5/11/2017 2:59:59 AM

Subject:
CN="Smart Finekspert, TOV", OU=IT, O="Smart Finekspert, TOV", STREET="Dekabrystiv, 38A/9", L=Mykolayiv, S=Mykolayivska, PostalCode=54017, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00BD1565E46FC9A8BAC048A4ADB2F69AE1

File PE Metadata
Compilation timestamp:
10/10/2010 1:25:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x31E18

Entry point:
E8, 69, 11, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C8, 02, 44, 00, E8, 02, 17, 00, 00, E8, 3A, 13, 00, 00, 0F, B7, F0, 6A, 02, E8, FC, 10, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, BB, 08, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
235.5 KB (241,152 bytes)

Remove setup.exe - Powered by Reason Core Security