setup_adobe_reader.exe

Adobe Reader

Install Helper

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application setup_adobe_reader.exe by Install Helper has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the Vittalia DM installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Install Helper  (signed and verified)

Product:
Adobe Reader

Version:
3.0.0.104

MD5:
a5eac6dc9bc6300e32bb604126a45bbd

SHA-1:
c54137930afe179ea4e9530ac32b58096d910f4e

SHA-256:
fe87e45e0586d90e1d09b61bc157aa4b2ddfea08d624fb9e312c241ce3c7e912

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 1:24:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.AirInstaller.5
5758502

AhnLab V3 Security
PUP/Win32.Bundler
2015.06.17

Avira AntiVirus
TR/Crypt.XPACK.Gen
7.11.30.172

Arcabit
Trojan.Application.Bundler.AirInstaller.5
1.0.0.425

AVG
Generic
2016.0.3076

Bitdefender
Gen:Variant.Application.Bundler.AirInstaller.5
1.0.20.840

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
Application.Win32.DownloadAssistant.S
22480

Dr.Web
Trojan.Vittalia.76
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.AirInstaller
10.0.0.5366

ESET NOD32
Win32/DownloadAssistant.A potentially unwanted application
7.0.302.0

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.14.151

G Data
Gen:Variant.Application.Bundler.AirInstaller
15.6.25

K7 AntiVirus
Unwanted-Program
13.205.16270

Malwarebytes
PUP.Optional.InstallHelper.C
v2015.06.17.10

MicroWorld eScan
Gen:Variant.Application.Bundler.AirInstaller.5
16.0.0.504

NANO AntiVirus
Trojan.Win32.Vittalia.dqfrig
0.30.24.2086

Norman
Gen:Variant.Application.Bundler.AirInstaller.5
02.06.2015 14:23:46

Panda Antivirus
Trj/Genetic.gen
15.06.17.10

Reason Heuristics
PUP.Vittalia.Bundler
15.6.17.6

Rising Antivirus
PE:Malware.XPACK-HIE/Heur!1.9C48
23.00.65.15615

VIPRE Antivirus
Threat.4782985
40786

File size:
961.1 KB (984,184 bytes)

Product version:
3.0.0.104

Copyright:
(c) Install Helper

Original file name:
setup_adobe_reader.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM

Language:
English (United States)

Common path:
C:\users\{user}\downloads\setup_adobe_reader.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
5/20/2015 1:00:00 AM

Valid to:
5/20/2016 12:59:59 AM

Subject:
CN=Install Helper, O=Install Helper, L=Vancouver, S=British Columbia, C=CA

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
0575634D1B3373331074EB7C4751AB12

File PE Metadata
Compilation timestamp:
5/28/2015 11:33:21 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:HrnIvCZBPho9L/R7iArsHr1MbFdlolFtiC+4:TwCb4/RMEIW4

Entry address:
0x126A

Entry point:
55, 8B, EC, 83, EC, 10, 53, 56, 57, 6A, 00, FF, 15, 08, 10, 49, 00, 8B, F8, 33, D2, 8B, CF, 8B, 5F, 3C, 03, DF, 2B, 05, 1C, 10, 40, 00, 89, 45, F4, 1B, D2, F7, D8, 89, 55, F8, 0F, B7, 73, 14, 83, D2, 00, F7, DA, 89, 75, F0, 52, 8B, 93, A0, 00, 00, 00, 50, 8B, 44, 1E, 24, 03, 05, 28, 10, 40, 00, 50, FF, B3, A4, 00, 00, 00, E8, 88, FD, FF, FF, 8B, 54, 1E, 28, 83, C4, 10, A1, 28, 10, 40, 00, 2B, D0, 83, FA, 01, 76, 0D, 8B, 4C, 1E, 24, 03, C8, 03, CF, E8, F2, FE, FF, FF, A1, 20, 10, 40, 00, 83, C6, 40, 03, F3...
 
[+]

Entropy:
7.0528

Developed / compiled with:
Microsoft Visual C++

Code size:
574 KB (587,776 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to useast.gtdlrfwd.com  (104.131.2.201:80)

TCP (HTTP):
Connects to new-york-2.cdn77.com  (92.242.140.21:80)

TCP (HTTP):
Connects to ec2-54-68-129-119.us-west-2.compute.amazonaws.com  (54.68.129.119:80)

Remove setup_adobe_reader.exe - Powered by Reason Core Security