ccdisksetup.exe

CCDisk

Youngzsoft Co., Ltd.

The application ccdisksetup.exe, “CCDisk Setup ” by Youngzsoft Co. has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from user.youngzsoft.com.
Publisher:
www.ccdisk.com   (signed by Youngzsoft Co., Ltd.)

Product:
CCDisk

Description:
CCDisk Setup

MD5:
91120c749ac5611958edeea46527329b

SHA-1:
22a3022f40aa6779d22d1c08f2d07398013420f4

SHA-256:
95eb3c66e633f4b65a8faa270a63146612f39c3a03c15d4e457c37531d93f54c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/3/2024 3:11:49 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.3.5.15

File size:
4.9 MB (5,113,376 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Turkish (Turkey)

Common path:
C:\users\{user}\downloads\ccdisksetup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2015 2:00:00 AM

Valid to:
5/15/2018 1:59:59 AM

Subject:
CN="Youngzsoft Co., Ltd.", OU=Software Development, O="Youngzsoft Co., Ltd.", L=Changsha, S=Hunan, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
72D5CAF59A3CC644C573E13EA0892EAB

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file ccdisksetup.exe has been seen being distributed by the following URL.

http://user.youngzsoft.com/ccdisk/.../ccdisksetup.exe

Remove ccdisksetup.exe - Powered by Reason Core Security