setup.exe

Операционная система Microsoft Windows

LIV Konstrakshn, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable setup.exe, “Исполняемый файл для игры "Солитер"” has been detected as malware by 1 anti-virus scanner. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Microsoft Corporation  (signed by LIV Konstrakshn, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Солитер"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
81ed62c8c7df9668d28d3da99e6808cf

SHA-1:
c77dda3c60a434f868bad465764362acee797bed

SHA-256:
7eef05183b3bc5d333833da043b02114f25a11af8e03d4bb0e9f31449d415942

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/27/2024 9:43:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.12.17.6

File size:
2.3 MB (2,391,232 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
freecell.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup.rar \setup\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/17/2016 3:00:00 AM

Valid to:
7/24/2017 2:59:59 AM

Subject:
CN="LIV Konstrakshn, TOV", OU=IT, O="LIV Konstrakshn, TOV", STREET="Vulytsya Kirovogradska, Budynok 38/58", STREET=Ofis 15, L=Kyyiv, S=Kyyiv, PostalCode=03069, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
359EF61F4B8E0D1D893C09DFE3350A18

File PE Metadata
Compilation timestamp:
6/7/2014 11:26:40 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x437C8

Entry point:
6A, 70, 68, 98, 70, 44, 00, E8, D0, 01, 00, 00, 33, DB, 53, 8B, 3D, 0C, 70, 44, 00, FF, D7, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 5D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, 99, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, 99, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 5D, FC, 6A, 02, FF, 15, 38, 70, 44, 00, 59, 83, 0D, 20, C7, 80, 00, FF, 83, 0D, 24, C7...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
277 KB (283,648 bytes)

Remove setup.exe - Powered by Reason Core Security