Setup.exe

UKRREMBUDSERVIS LTD

This is a component of the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by UKRREMBUDSERVIS has been detected as adware by 20 anti-malware scanners. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
UKRREMBUDSERVIS LTD  (signed and verified)

MD5:
213239d05ae4dfb0036c2c552b3e9678

SHA-1:
c56f475b8899d58effe14438c42313069e8d5bdc

SHA-256:
a0620bc68be07cd33f3053bfeaed8cf9b12ba935f6e9d19f061c8ebd9f78877a

Scanner detections:
20 / 68

Status:
Adware

Analysis date:
11/27/2024 10:41:53 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.12439
5943376

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Bundler
2015.04.28

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150505

AVG
Generic
2016.0.3118

Bitdefender
Gen:Variant.Mikey.12439
1.0.20.625

Dr.Web
Adware.Downware.9625
9.0.1.0125

Emsisoft Anti-Malware
Gen:Variant.Mikey.12439
9.0.0.4799

ESET NOD32
Win32/Bundlore.T potentially unwanted application
9.7.0.302.0

F-Prot
W32/S-b5ba81db
v6.4.7.1.166

F-Secure
Gen:Variant.Mikey.12439
5.13.68

G Data
Gen:Variant.Mikey.12439
15.5.25

K7 AntiVirus
Unwanted-Program
13.203.15813

McAfee
Program.PUP-FOZ
5600.6774

MicroWorld eScan
Gen:Variant.Mikey.12439
16.0.0.375

NANO AntiVirus
Riskware.Win32.Downware.dqttqr
0.30.20.1219

Panda Antivirus
Trj/Genetic.gen
15.05.05.09

Reason Heuristics
Threat.Win.Reputation.IMP
15.5.5.16

VIPRE Antivirus
Threat.4150696
39676

File size:
359.5 KB (368,136 bytes)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/22/2015 8:00:00 PM

Valid to:
3/22/2016 7:59:59 PM

Subject:
CN="""UKRREMBUDSERVIS"" LTD", O="""UKRREMBUDSERVIS"" LTD", STREET="Stepana Sahaydaka str, 100-A", L=Kiev, S=Kiev, PostalCode=02002, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2275F2D622D08DDBED9ABADB3884FAA5

File PE Metadata
Compilation timestamp:
4/22/2015 4:27:28 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:AzQTS8h7PMcLxEH2uBDhvgeVGu2DqYpf5zVvQV2FIBy:n9DMc1EH2uhhvgUAqYpf5zVvQV2FIBy

Entry address:
0x7A8D

Entry point:
E8, 66, 5B, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, CF, 42, 00, E8, 9D, 48, 00, 00, E8, 37, 5D, 00, 00, 0F, B7, F0, 6A, 02, E8, F9, 5A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 62, 43, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.9885

Code size:
141 KB (144,384 bytes)

Remove Setup.exe - Powered by Reason Core Security