setup_790.exe

wUOL

wU

The application setup_790.exe has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from dl.cetaitlagrenouille.com.
Publisher:
wU

Product:
wUOL

Description:
wUOLWOQMX

Version:
0.1.8.5

MD5:
0af9326839bb891ee82cb4888a1ef0d7

SHA-1:
31a99b59e88d25c2ef4ee0e842d6397c7730769b

SHA-256:
a14c018fe10824207d7cbe9e37feb1d5aa54e5f0c1a9827fd5b82a1755bda750

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/28/2024 1:38:26 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
160518-2

Dr.Web
Adware.Eorezo.898
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Temonde
16.06.12

ESET NOD32
MSIL/Injector.ORY trojan
8.0.319.0

Reason Heuristics
Adware.Eorezo.DB (M)
16.6.12.10

File size:
925 KB (947,200 bytes)

Product version:
0.1.8.5

Copyright:
wU2016

Trademarks:
wUO

Original file name:
MicFightPr.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\users\{user}\appdata\local\temp\setup_790.exe

File PE Metadata
Compilation timestamp:
6/7/2016 9:46:49 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
48.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Ybkx0nno5g/1gMOcZOT374BPfxxaPCrJmQ7agGsfWD5Uv3fipr9UF8n:CksfYcmUxfdrskagG5v

Entry address:
0x8D496

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Code size:
557.5 KB (570,880 bytes)

The file setup_790.exe has been seen being distributed by the following URL.

Remove setup_790.exe - Powered by Reason Core Security