Setup.exe

SmileFiles Installer

Nedonte Inc

The file Setup.exe by Nedonte Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
http://smile-files.com  (signed by Nedonte Inc)

Product:
SmileFiles Installer

Version:
1, 0, 643, 1

MD5:
f564390d5ea70fdcfa6841309e3ddf05

SHA-1:
c56b67244a636915ad9586a02cb2d28486ff214d

SHA-256:
e47fd99b91ac3b2d3cb2d29b733514b14599cc17ca8ef7cfe4e8785e570ba920

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 2:45:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ExpressDownloader (M)
16.11.7.4

File size:
3.2 MB (3,405,896 bytes)

Product version:
1.0.0.1

Copyright:
Copyright http://smile-files.com (C) 2014

Original file name:
SmileFiles.exe

Language:
English

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/18/2014 1:00:00 AM

Valid to:
12/22/2016 1:00:00 PM

Subject:
CN=Nedonte Inc, O=Nedonte Inc, L=Mahe, C=SC

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
05EF10CC32145EAD5B15575FD0B9EF79

File PE Metadata
Compilation timestamp:
4/9/2015 12:06:58 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
98304:ee1YyqtQX/uJfGZPlc3GvgbawWj36+dufwQYkg:VeCmgUbaXj2YQYkg

Entry address:
0x446FF0

Entry point:
E8, 1E, 17, D6, FF, 66, 0F, A3, E5, E8, 06, 33, D1, FF, C0, E1, EC, E0, 25, A3, 6D, 59, 86, 67, A4, 25, CE, 90, 18, 64, 79, 2F, 5E, 96, 6F, 71, 3C, A1, 14, DC, F1, DC, E9, D7, E6, 06, EF, 05, 00, E8, 05, BB, 25, EF, 82, 0C, 29, BC, D8, 3A, FC, 7D, 1E, 05, 54, 51, 6F, 77, 0E, 85, 83, 6F, 50, 5D, 26, DD, D3, C4, 4C, B4, EC, 4A, 96, 82, 60, 37, D9, 41, 9D, FA, 1C, 86, BB, 22, 68, 26, EF, 98, 15, 81, 32, 18, E2, AB, B1, 86, 28, 00, 92, CB, E2, F5, 87, 87, 2E, 18, 3C, E5, 97, E6, 07, 4D, AD, 95, 28, DA, 0B, 71...
 
[+]

Code size:
802.5 KB (821,760 bytes)

Remove Setup.exe - Powered by Reason Core Security