wpsetup.exe

WinPatrol

BillP Studios

The program is a setup application that uses the Tarma Installer installer. The file has been seen being downloaded from filehippo.com and multiple other hosts.
Publisher:
BillP Studios  (signed and verified)

Product:
WinPatrol

Description:
Installer for WinPatrol

Version:
2014.6.3.1711

MD5:
ac1c4b0e8735e59c571564668655917d

SHA-1:
7e7ba9a6e80646b7c791193071da11b45e3dd18e

SHA-256:
4ccaf6dded6da29349490838e8569c8b2a0f648ad5953b32f3d0bc42e2be7255

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/25/2024 6:31:47 AM UTC  (today)

File size:
1 MB (1,064,488 bytes)

Product version:
31.0.2014.0

Copyright:
Copyright © 1997-2014 BillP Studios

Original file name:
TSULoader.exe

File type:
Executable application (Win32 EXE)

Installer:
Tarma Installer

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\wpsetup.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/10/2013 8:00:00 PM

Valid to:
8/10/2014 7:59:59 PM

Subject:
CN=BillP Studios, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=BillP Studios, L=Scotia, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5979CE6757EEE9091D841E4D73F6A021

File PE Metadata
Compilation timestamp:
3/12/2013 4:51:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:s7RGhShmRcUvBzwCBkJgB7ZjezdDgOgSJNkW54XJeT1ksqrpE8nc6v:sQAmzwoB7czdjgS3B4XKSsq1Ej6v

Entry address:
0x14D8

Entry point:
55, 8B, EC, 81, EC, 20, 03, 00, 00, 53, 56, 33, DB, 57, C6, 85, E4, FD, FF, FF, 00, 89, 5D, F8, 89, 5D, FC, FF, 15, 78, 30, 40, 00, A3, 08, 44, 40, 00, FF, 15, 74, 30, 40, 00, 8B, F8, 8D, 45, EC, 50, FF, 15, 70, 30, 40, 00, FF, 15, 6C, 30, 40, 00, 8B, F0, F7, D6, 33, F7, FF, 15, 68, 30, 40, 00, 33, F0, 8B, 45, F0, 33, 45, EC, 68, 04, 01, 00, 00, 33, F0, 8D, 85, E0, FC, FF, FF, 50, 53, FF, 15, 64, 30, 40, 00, 85, C0, 75, 22, FF, 15, 60, 30, 40, 00, 50, 68, 44, 32, 40, 00, E8, 44, FB, FF, FF, 59, 59, C7, 05...
 
[+]

Entropy:
7.9730

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file wpsetup.exe has been discovered within the following program.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
 
Powered by Should I Remove It?

The file wpsetup.exe has been seen being distributed by the following 10 URLs.

Scan wpsetup.exe - Powered by Reason Core Security