setup.exe

Bundlore LTD

This is the Bundlore download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup.exe, “Any Media Converter setup” by Bundlore has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the Bundlore Downloader installer. The file has been seen being downloaded from dec.pcvideosfreedownload.com and multiple other hosts.
Publisher:
Any Media Converter  (signed by Bundlore LTD)

Product:
Any Media Converter

Description:
Any Media Converter setup

Version:
1.14

MD5:
f1106d512380d0a9eb8df8e0d98076ef

SHA-1:
fce478d3a8a64952c0e543fcd82abd7a5cc7c511

SHA-256:
2fd6d0aa0c37a2346e3a85c5b409bbd5bb23b38b14ae754e8fc5fd46e2a1de7d

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/5/2024 4:41:26 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Downware.514
9.0.1.0146

ESET NOD32
Win32/Toolbar.Conduit
8.9722

Panda Antivirus
PUP/Conduit.A
14.05.26.10

Reason Heuristics
PUP.Installer.Bundlore.F
14.8.7.20

Vba32 AntiVirus
suspected of Trojan.Downloader.gen.h
3.12.26.0

VIPRE Antivirus
Wajam
28596

File size:
602.3 KB (616,760 bytes)

Copyright:
© Any Media Converter (Converter_I150_AUTO_NICE_SIGNED_WITHPOST)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Bundlore Downloader (using Nullsoft Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/5/2012 2:00:00 AM

Valid to:
7/6/2014 1:59:59 AM

Subject:
CN=Bundlore LTD, O=Bundlore LTD, STREET=Beit Oved 9, L=Tel Aviv, S=Israel, PostalCode=67211, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
0C7A8094C56AAFE39F3CA37C7F65AC84

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ZeD/TZXEmHY3GFMxjJto9lJH4QcQtAbhFyXZFSPCVVDr0qI:ZeLTJwjJ2nJYHg6hFyXDVD5

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file setup.exe has been seen being distributed by the following 2 URLs.

Remove setup.exe - Powered by Reason Core Security