codecperformersetup.exe

Installer

YellowSoft Inc

This is the Performersoft setup installer. The application codecperformersetup.exe by YellowSoft Inc has been detected as adware by 38 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.softologicsb.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
YellowSoft Inc  (signed and verified)

Product:
Installer

Version:
15.9.28.27

MD5:
7ced0087842036568cf0b1b0bb236890

SHA-1:
4b8b54550f395b8dac71033ae01ec9aca2d17c24

SHA-256:
00a93f6e8c6628abe95077b605db98a0775d9d05ee3f269c758e4836d761b5ce

Scanner detections:
38 / 68

Status:
Adware

Explanation:
Uses the InstallBrain monetization platform from iBario to deliver bundled adware both search toolbars and PC optimizers from Performersoft.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 10:55:03 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.InstallBrain.A
384

Agnitum Outpost
Adware.BrainInst
7.1.1

AhnLab V3 Security
Adware/Win32.BrainInst
16.01.17

Avira AntiVirus
APPL/InstallBrain.Gen
7.11.144.152

avast!
Win32:Installer-AB [PUP]
2014.9-160117

AVG
Trojan horse Downloader.Generic13
2017.0.2862

Bitdefender
Application.Bundler.InstallBrain.A
1.0.20.85

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Installbrain-270
0.98/20157

Comodo Security
TrojWare.Win32.Brantall.A
18140

Dr.Web
Adware.Downware.1522
9.0.1.017

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.131298
8.16.01.17.09

ESET NOD32
Win32/InstallBrain.AV (variant)
10.9702

Fortinet FortiGate
Adware/BrainInst
1/17/2016

F-Prot
W32/IBrain.B2.gen
v6.4.7.1.166

F-Secure
Application.Bundler.InstallBrain
11.2016-17-01_1

G Data
Application.Bundler.InstallBrain
16.1.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Trojan-Downloader
13.176.11524

Kaspersky
Trojan-Downloader.Win32.BrainInst
14.0.0.803

Malwarebytes
Adware.InstallBrain
v2016.01.17.09

McAfee
PUP-FDT!EEF04BF470C2
5600.6518

Microsoft Security Essentials
Threat.Undefined
1.173.2153.0

MicroWorld eScan
Application.Bundler.InstallBrain.A
17.0.0.51

NANO AntiVirus
Trojan.Win32.Downware.cqhnzm
0.28.0.59288

Norman
Application.Bundler.InstallBrain.A
11.20160117

nProtect
Trojan-Downloader/W32.BrainInst.875416
14.03.21.01

Panda Antivirus
PUP/Ibups
16.01.17.09

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Quick Heal
TrojanDownloader.Brantall.A5
1.16.12.00

Reason Heuristics
PUP.Performersoft.YellowSoft.Bundler (M)
16.1.17.9

Rising Antivirus
PE:Trojan.Brantall!6.100B
23.00.65.16115

Sophos
InstallBrain
4.98

SUPERAntiSpyware
PUP.InstallBrain/Variant
9380

Total Defense
Win32/Tnega.ICFFLHD
37.0.10889

Vba32 AntiVirus
TrojanDownloader.BrainInst
3.12.26.0

VIPRE Antivirus
InstallBrain
28448

Zillya! Antivirus
Downloader.BrainInst.Win32.7
2.0.0.1790

File size:
789.9 KB (808,856 bytes)

Product version:
15.9.28.27

Copyright:
Copyright 2012

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\users\{user}\downloads\codecperformersetup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/11/2012 10:45:31 PM

Valid to:
9/11/2015 10:45:31 PM

Subject:
CN=YellowSoft Inc, O=YellowSoft Inc, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EC8FFEF413CDC

File PE Metadata
Compilation timestamp:
10/16/2013 5:09:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:iwVYf3l/nqOTsdU+Rki09XThJSmzDN6BvqA9u6o4FCfGPbpy1GjxGnP7Rd3NmB:d6PNTsYnmvpRd6gy1Q4nP7Rd3NmB

Entry address:
0xC02D

Entry point:
E8, EE, 4B, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, C8, 45, 42, 00, 00, 75, 18, E8, 39, 44, 00, 00, 6A, 1E, E8, 83, 42, 00, 00, 68, FF, 00, 00, 00, E8, A9, 2B, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, C8, 45, 42, 00, FF, 15, 50, A0, 41, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, CC, 45, 42, 00, 74, 0D, 53, E8, 11, 2A, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, E3, 29, 00, 00, 89, 30, E8, DC, 29, 00, 00, 89...
 
[+]

Entropy:
7.8021  (probably packed)

Code size:
98 KB (100,352 bytes)

The file codecperformersetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove codecperformersetup.exe - Powered by Reason Core Security