yosetup_rc.exe

Pavel Repkin

The application yosetup_rc.exe by Pavel Repkin has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
Pavel Repkin  (signed and verified)

MD5:
df5eed1df6d4e7b1c83aefc4265b854c

SHA-1:
ef4e06ca970cb52fd9440436f83ef7d1cfdb8021

SHA-256:
c905096e8483b19fcbecc861cae13a1d6116017a04fc7f2600294deaf81ada56

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
11/12/2024 6:52:12 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.OpenCandy
4.0.3.15824

ESET NOD32
9.10698

G Data
Win32.Adware.OpenCandy
15.8.24

Malwarebytes
PUP.Optional.OpenCandy
v2015.08.24.11

NANO AntiVirus
Trojan.Win32.OpenCandy.bkcnyj
0.28.6.62995

Reason Heuristics
PUP.PavelRepkin.Installer (M)
15.8.24.11

Trend Micro House Call
Suspicious_GEN.F47V1029
7.2.236

VIPRE Antivirus
Opencandy
34666

File size:
7.4 MB (7,801,240 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
8/30/2011 5:17:25 AM

Valid to:
8/30/2013 12:50:27 PM

Subject:
E=pavel.repkin@gmail.com, CN=Pavel Repkin, L=Saint Petersburg, S=Saint Petersburg City, C=RU, Description=496726-6lnbyJoXvJM0x5wb

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
03ED

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:J6Fj4ESzI8FETpiqV/UZD8eFiR2TPtM6vI+W6wW:J24EatETcqxUlIw26nwW

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove yosetup_rc.exe - Powered by Reason Core Security