yosetup.exe

Pavel Repkin

The application yosetup.exe by Pavel Repkin has been detected as adware by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
Pavel Repkin  (signed and verified)

MD5:
19b84d2bd9c241bd01ab680a68f67810

SHA-1:
b9eb84383bcf7b2bea235c2ea628e548d6589faa

SHA-256:
516825325572cd387b7aa0ffee4ae8f891950b0f9be6ba7b5449db218af50842

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
11/12/2024 6:33:19 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
8.8678

Malwarebytes
PUP.Optional.OpenCandy
v2014.03.25.02

Reason Heuristics
PUP.Installer.PavelRepkin.H
14.3.25.14

Trend Micro House Call
TROJ_GEN.F47V0730
7.2.84

File size:
7.7 MB (8,063,232 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\yosetup.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
8/30/2011 4:17:25 AM

Valid to:
8/30/2013 11:50:27 AM

Subject:
E=pavel.repkin@gmail.com, CN=Pavel Repkin, L=Saint Petersburg, S=Saint Petersburg City, C=RU, Description=496726-6lnbyJoXvJM0x5wb

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
03ED

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:AVi4/H8q3LQPcHV/UXD8eRBsWiQ9nN6vIVvuR:ei4/H8q3LZxUz7ZN626

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove yosetup.exe - Powered by Reason Core Security