setup.exe

The executable setup.exe has been detected as malware by 17 anti-virus scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DesktopVerifyer’. The file has been seen being downloaded from youtube.com and multiple other hosts.
MD5:
c809084c8a442b90b1cea5c93b170ccd

SHA-1:
d5f7100704ac0872db4fdb575833b26b4b9499e5

SHA-256:
ca541c745f5772b14fdeddf26a522175acaf0ebacbb6e89ccd6bc2529c8caa42

Scanner detections:
17 / 68

Status:
Malware

Analysis date:
1/12/2025 12:08:17 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Kazy.619267
607

Avira AntiVirus
TR/Crypt.Xpack.233897
8.3.1.6

AVG
Inject2
2016.0.3085

Bitdefender
Gen:Variant.Kazy.619267
1.0.20.795

Dr.Web
Trojan.Winlock.12112
9.0.1.0159

Emsisoft Anti-Malware
Gen:Variant.Kazy.619267
8.15.06.08.03

ESET NOD32
Win32/Injector.CBDY (variant)
9.11671

Fortinet FortiGate
W32/Injector.CBBC!tr
6/8/2015

F-Secure
Gen:Variant.Kazy.619267
11.2015-08-06_2

G Data
Gen:Variant.Kazy.619267
15.6.25

Malwarebytes
Trojan.Agent.ED
v2015.06.08.03

McAfee
Artemis!C809084C8A44
5600.6741

MicroWorld eScan
Gen:Variant.Kazy.619267
16.0.0.477

Norman
Injector.GLFH
11.20150608

Panda Antivirus
Trj/Genetic.gen
15.06.08.03

Qihoo 360 Security
HEUR/QVM19.1.Malware.Gen
1.0.0.1015

Rising Antivirus
PE:Malware.Obscure!1.9C59
23.00.65.15606

File size:
1.5 MB (1,571,882 bytes)

File type:
Executable application (Win64 EXE)

File PE Metadata
Compilation timestamp:
5/8/2015 7:12:51 PM

OS version:
13.9

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
1.1

CTPH (ssdeep):
24576:6UxNjnvv0tl6L6YjErKXF4lua0/fPdi/rMWteF7WScb43oCFSMhby2yjFB:dLU7PYjaUKluavTVteF7Is3V7nQFB

Entry address:
0x5D76

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, E8, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9780  (probably packed)

Code size:
24 KB (24,577 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DesktopVerifyer

Command:
C:\master\power point\setup.exe


The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security