setup.zip

The file setup.zip has been detected as a potentially unwanted program by 17 anti-malware scanners. It uses the Solimba download manager to push adware offers during the download and setup process. Bundled adware includes search and shopping web browser toolbars. The file has been seen being downloaded from gu.f1l3pzivrubajjui.com.
MD5:
e980636ed3e812242f8078fb0738743e

SHA-1:
145ac8764e67781ed38a755cb1e624603c90cdf3

SHA-256:
4b14e368c2aaad47527edf9205d4debd42c1a7f401f17af56c4e17008c02eb4a

Scanner detections:
17 / 68

Status:
Potentially unwanted

Explanation:
Uses the Solimba installer to bundle adware offers.

Analysis date:
11/15/2024 1:00:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Graftor.190520
5811808

Avira AntiVirus
TR/PWS.Sinowal.Gen
8.3.2.2

Arcabit
Trojan.Adware.Graftor.D2E838
1.0.0.425

avast!
Win32:Downloader-WAX [PUP]
2014.9-150825

AVG
Generic
2016.0.3006

Bitdefender
Gen:Variant.Adware.Graftor.190520
1.0.20.1185

Dr.Web
infected with Trojan.Solimba.1
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.190520
10.0.0.5366

ESET NOD32
Win32/Solimba.C potentially unwanted application
7.0.302.0

F-Secure
Gen:Variant.Adware.Graftor
11.2015-25-08_3

G Data
Gen:Variant.Adware.Graftor.190520
15.8.25

IKARUS anti.virus
Trojan-Dropper.Win32.Sventore
t3scan.1.9.5.0

Kaspersky
not-a-virus:Downloader.Win32.Morstar
15.0.0.543

MicroWorld eScan
Gen:Variant.Adware.Graftor.190520
16.0.0.711

NANO AntiVirus
Trojan.Win32.Solimba.dvbsyz
0.30.24.3079

Norman
Gen:Variant.Adware.Graftor.190520
04.08.2015 10:30:46

VIPRE Antivirus
Solimba
43204

File size:
513.4 KB (525,729 bytes)

Common path:
C:\users\{user}\downloads\setup.zip

The file setup.zip has been seen being distributed by the following URL.

Remove setup.zip - Powered by Reason Core Security