Setup.exe

UKRREMBUDSERVIS LTD

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file Setup.exe by UKRREMBUDSERVIS has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
UKRREMBUDSERVIS LTD  (signed and verified)

MD5:
a574ba42c01c9a6096df49c6b1453b58

SHA-1:
deaa3c09fa0f9982e401048be9760001c5df7227

SHA-256:
a94702f7d7ceeeae63e175b89694b3ff55595dd3e369f395244e38e37843c410

Scanner detections:
10 / 68

Status:
Adware

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
1/18/2025 11:31:29 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
150414-0

AVG
BundleApp
2016.0.3132

Dr.Web
Adware.Downware.9625
9.0.1.05190

ESET NOD32
Win32/Bundlore.T potentially unwanted application
7.0.302.0

McAfee
Program.PUP-FOZ
16.8.708.2

NANO AntiVirus
Riskware.Win32.Downware.dqthbk
0.30.20.1219

Panda Antivirus
Trj/Genetic.gen
15.04.22.01

Reason Heuristics
Threat.Win.Reputation.IMP
15.4.21.20

VIPRE Antivirus
Threat.4150696
39354

File size:
359.5 KB (368,136 bytes)

Bundler/Installer:
Bundlore Downloader

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/22/2015 7:00:00 PM

Valid to:
3/22/2016 6:59:59 PM

Subject:
CN="""UKRREMBUDSERVIS"" LTD", O="""UKRREMBUDSERVIS"" LTD", STREET="Stepana Sahaydaka str, 100-A", L=Kiev, S=Kiev, PostalCode=02002, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2275F2D622D08DDBED9ABADB3884FAA5

File PE Metadata
Compilation timestamp:
4/18/2015 1:18:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
6144:e21Ge8hA4khwMcLxbH2TnxEP2kinnPtomf7JtT6:eiCIyMc1bH2T2PHinnPCmfNR6

Entry address:
0x7ABD

Entry point:
E8, E6, 5A, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 98, CF, 42, 00, E8, 1D, 48, 00, 00, E8, B7, 5C, 00, 00, 0F, B7, F0, 6A, 02, E8, 79, 5A, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, EE, 42, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.0116

Code size:
141 KB (144,384 bytes)

Remove Setup.exe - Powered by Reason Core Security