setup_adobe_reader.exe

Adobe Reader

Install Helper

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup_adobe_reader.exe by Install Helper has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from files.1download.io.
Publisher:
Install Helper  (signed and verified)

Product:
Adobe Reader

Version:
3.0.0.104

MD5:
0ec998871dcd95f895da4a49721913f3

SHA-1:
bd267831fee38019333eb9fc341c6ca089aa08aa

SHA-256:
116812abd9132019689eb027758ed43fd43311a07724bd6c9b7c17d4818c9011

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/4/2024 5:04:52 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.5
5582423

AhnLab V3 Security
PUP/Win32.Bundler
2015.05.30

Avira AntiVirus
TR/Crypt.XPACK.Gen
8.3.1.6

AVG
Generic
2016.0.3094

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.5
1.0.20.745

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.DownloadAssistant.S
22268

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
15.05.29

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.14.151

G Data
Gen:Variant.Application.Bundler.AirInstaller
15.5.25

Malwarebytes
PUP.Optional.InstallHelper.C
v2015.05.29.04

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.5
16.0.0.447

NANO AntiVirus
Trojan.Win32.Vittalia.dqfrig
0.30.24.1636

Norman
Gen:Variant.Application.Bundler.AirInstaller.5
03.12.2014 13:20:04

Panda Antivirus
Trj/Genetic.gen
15.05.29.04

Reason Heuristics
PUP.Vittalia.Bundler
15.5.29.12

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15527

VIPRE Antivirus
Threat.4782985
40552

File size:
961.1 KB (984,184 bytes)

Product version:
3.0.0.104

Copyright:
(c) Install Helper

Original file name:
setup_adobe_reader.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup_adobe_reader.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/20/2015 1:00:00 AM

Valid to:
5/20/2016 12:59:59 AM

Subject:
CN=Install Helper, O=Install Helper, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0575634D1B3373331074EB7C4751AB12

File PE Metadata
Compilation timestamp:
5/29/2015 4:53:05 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:dPkbzONyZsNuxUyH10WcjyfzwvJo6fuRB5ZeTFe:ozONyZUuxL6juiAGRe

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 10, 49, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0528

Developed / compiled with:
Microsoft Visual C++

Code size:
574 KB (587,776 bytes)

The file setup_adobe_reader.exe has been seen being distributed by the following URL.

Remove setup_adobe_reader.exe - Powered by Reason Core Security