setup.exe

Chromium

Limited Liability Company Ucoz Media

The application setup.exe by Limited Liability Company Ucoz Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This is the uninstaller utility registered in the Windows Control Panel for the program Uran by Uran.
Publisher:
The Chromium Authors  (signed by Limited Liability Company Ucoz Media)

Product:
Chromium

Version:
22.0.1229.79

MD5:
24da728ecac239604a9a5fbbd5b05f5b

SHA-1:
f17fd7517338f037d0c46f14185d990f4c5a6af9

SHA-256:
b6537188a1934952560543ef54e4b7a1c29ebf28c4d6016e0905784472cdfdc7

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 4:08:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Installer.LimitedLiabilityCompanyUcozMedia
15.3.20.18

File size:
1.6 MB (1,650,136 bytes)

Product version:
22.0.1229.79

Copyright:
Copyright (C) 2006-2010 The Chromium Authors. All Rights Reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\uran\application\22.0.1229.79\installer\setup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/16/2012 11:17:49 PM

Valid to:
3/17/2014 11:17:49 PM

Subject:
E=alexzander@ucoz.com, CN=Limited Liability Company Ucoz Media, OU=Bagrationovskiy proyezd, O=Limited Liability Company Ucoz Media, L=Moscow, S=Moscow, C=RU

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121B28BB43AF25490AA12229BA614435817

File PE Metadata
Compilation timestamp:
10/4/2012 1:10:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:CnyMYmiH692trRMApK8iu88Ozw5vlaaqw1gyy+2NrdJ4POOlylG:8ylmgBta8ONwWtw14+CrdJ+xoG

Entry address:
0xBF56D

Entry point:
E8, 57, B1, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 56, 8B, F1, C6, 46, 0C, 00, 85, C0, 75, 63, E8, 13, 87, 00, 00, 89, 46, 08, 8B, 48, 6C, 89, 0E, 8B, 48, 68, 89, 4E, 04, 8B, 0E, 3B, 0D, B8, 97, 52, 00, 74, 12, 8B, 0D, 70, 95, 52, 00, 85, 48, 70, 75, 07, E8, C2, 84, 00, 00, 89, 06, 8B, 46, 04, 3B, 05, 68, 9C, 52, 00, 74, 16, 8B, 46, 08, 8B, 0D, 70, 95, 52, 00, 85, 48, 70, 75, 08, E8, B0, B3, 00, 00, 89, 46, 04, 8B, 46, 08, F6, 40, 70, 02, 75, 14, 83, 48, 70, 02, C6, 46, 0C, 01, EB, 0A...
 
[+]

Code size:
879 KB (900,096 bytes)

Program Uninstaller
Program name:
Uran

Display publisher:
Uran

Display version:
22.0.1229.79

Uninstall string:
"C:\users\{user}\appdata\local\uran\application\22.0.1229.79\installer\setup.exe" --uninstall --verbose-logging


Remove setup.exe - Powered by Reason Core Security