codecperformersetup.exe

Installer

YellowSoft Inc

This is the Performersoft setup installer. The application codecperformersetup.exe by YellowSoft Inc has been detected as adware by 38 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from www.softologicsb.com. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
YellowSoft Inc  (signed and verified)

Product:
Installer

Version:
15.9.28.27

MD5:
d47a689bb724cc38dad0b5c0f0cdb7a0

SHA-1:
95f8bb74616655f2b85499fe0deac6ae4a4ed9c4

SHA-256:
0fa2efd1927c49c6cde98d82960ad1cb1bc6b82149d5e396f1ba26ea2051f443

Scanner detections:
38 / 68

Status:
Adware

Explanation:
Uses the InstallBrain monetization platform from iBario to deliver bundled adware both search toolbars and PC optimizers from Performersoft.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/19/2024 2:00:31 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.InstallBrain.A
388

Agnitum Outpost
Adware.BrainInst
7.1.1

AhnLab V3 Security
Adware/Win32.BrainInst
16.01.13

Avira AntiVirus
APPL/InstallBrain.Gen
7.11.144.152

avast!
Win32:Installer-AB [PUP]
2014.9-160113

AVG
Trojan horse Downloader.Generic13
2017.0.2866

Bitdefender
Application.Bundler.InstallBrain.A
1.0.20.65

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Installbrain-270
0.98/20157

Comodo Security
TrojWare.Win32.Brantall.A
18140

Dr.Web
Adware.Downware.1522
9.0.1.013

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.131298
8.16.01.13.06

ESET NOD32
Win32/InstallBrain.AV (variant)
10.9702

Fortinet FortiGate
Adware/BrainInst
1/13/2016

F-Prot
W32/IBrain.B2.gen
v6.4.7.1.166

F-Secure
Application.Bundler.InstallBrain
11.2016-13-01_4

G Data
Application.Bundler.InstallBrain
16.1.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Trojan-Downloader
13.176.11524

Kaspersky
Trojan-Downloader.Win32.BrainInst
14.0.0.824

Malwarebytes
Adware.InstallBrain
v2016.01.13.06

McAfee
PUP-FDT!EEF04BF470C2
5600.6522

Microsoft Security Essentials
Threat.Undefined
1.173.2153.0

MicroWorld eScan
Application.Bundler.InstallBrain.A
17.0.0.39

NANO AntiVirus
Trojan.Win32.Downware.cqhnzm
0.28.0.59288

Norman
Application.Bundler.InstallBrain.A
11.20160113

nProtect
Trojan-Downloader/W32.BrainInst.875416
14.03.21.01

Panda Antivirus
PUP/Ibups
16.01.13.06

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Quick Heal
TrojanDownloader.Brantall.A5
1.16.12.00

Reason Heuristics
PUP.Performersoft.YellowSoft.Bundler (M)
16.1.13.6

Rising Antivirus
PE:Trojan.Brantall!6.100B
23.00.65.16111

Sophos
InstallBrain
4.98

SUPERAntiSpyware
PUP.InstallBrain/Variant
9388

Total Defense
Win32/Tnega.ICFFLHD
37.0.10889

Vba32 AntiVirus
TrojanDownloader.BrainInst
3.12.26.0

VIPRE Antivirus
InstallBrain
28448

Zillya! Antivirus
Downloader.BrainInst.Win32.7
2.0.0.1790

File size:
854.9 KB (875,416 bytes)

Product version:
15.9.28.27

Copyright:
Copyright 2012

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\users\{user}\downloads\codecperformersetup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/12/2012 4:45:31 AM

Valid to:
9/12/2015 4:45:31 AM

Subject:
CN=YellowSoft Inc, O=YellowSoft Inc, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EC8FFEF413CDC

File PE Metadata
Compilation timestamp:
10/24/2013 7:27:57 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:7iMWqTyWEWJLIJC3YuGb+EPqrCM4x1ae47Rd3NH:erqTykqcwACM+weoL31

Entry address:
0xFEEC

Entry point:
E8, 3F, 82, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 4C, 31, 43, 00, 00, 75, 18, E8, 8A, 7A, 00, 00, 6A, 1E, E8, D4, 78, 00, 00, 68, FF, 00, 00, 00, E8, 7C, 72, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 4C, 31, 43, 00, FF, 15, 48, 50, 42, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, C4, 31, 43, 00, 74, 0D, 53, E8, AA, 39, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 4F, 01, 00, 00, 89, 30, E8, 48, 01, 00, 00, 89...
 
[+]

Code size:
143.5 KB (146,944 bytes)

The file codecperformersetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

TCP (HTTP):

Remove codecperformersetup.exe - Powered by Reason Core Security