Setup.exe

Program Installer

Internet app

The file Setup.exe, “Program Installer Setup ” has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
Internet app

Product:
Program Installer

Description:
Program Installer Setup

Version:
1.3.3.8

MD5:
853a4d48efdf583c29263822e2e75012

SHA-1:
ba383f1608e84aa1309f71b43e5616aab0ba173b

SHA-256:
73c71492ed8c98529f72b96e8c1e4a41a8796415763a1a0d9c369c083f074896

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/15/2024 1:56:17 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

AVG
Adware InstallCore.AIZ
2014.0.4311

Dr.Web
Trojan.InstallCore.721
9.0.1.05190

ESET NOD32
Win32/InstallCore.ZC potentially unwanted application
7.0.302.0

K7 AntiVirus
Adware
13.204.16076

NANO AntiVirus
Riskware.Win32.InstallCore.dsgvrb
0.30.24.1636

VIPRE Antivirus
Threat.4150696
40552

File size:
772.4 KB (790,984 bytes)

Product version:
5.0

Copyright:
App

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 4:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:KHEVPwaBMYTIxeXOE5iYm/4hwQyacPsErO+hH3:KkVP3TIxe75iY64hwQarp

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.8040

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

Remove Setup.exe - Powered by Reason Core Security