cyberlink_powerdirector_downloader.exe

CyberLink PowerDirector 13

Software Association LLC

The application cyberlink_powerdirector_downloader.exe by Software Association has been detected as a potentially unwanted program by 6 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from power-director.joydownload.com.
Publisher:
Software Association LLC  (signed and verified)

Product:
CyberLink PowerDirector 13

Version:
1.0.0.0

MD5:
0e5a1ad0a852acb11be1123bc8267a08

SHA-1:
7049d6d51422a5e64bb1f0387262cb9772e8732a

SHA-256:
e2c27470f1fc9bc523395ddaead00f94bfacc632d0165c1c678d6f15b47d87d6

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
5/6/2024 8:19:05 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
OpenCandy
2016.0.3212

ESET NOD32
Win32/OpenCandy.C potentially unsafe application
7.0.302.0

Malwarebytes
PUP.Optional.OpenCandy
v2015.01.31.01

McAfee
Trojan.Artemis!C40FC4A0A9DA
16.8.708.2

Trend Micro House Call
Suspici.F4CBE3E4
7.2.31

VIPRE Antivirus
Threat.4847482
36694

File size:
418.1 KB (428,136 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\cyberlink_powerdirector_downloader.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/13/2015 1:00:00 AM

Valid to:
1/21/2016 1:00:00 PM

Subject:
CN=Software Association LLC, O=Software Association LLC, L=Dnepropetrovsk, S=Dnipropetrovs'ka Oblast', C=UA

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0E1FC80B1C57AD69AA6F8D65D1CF90CF

File PE Metadata
Compilation timestamp:
5/20/2013 1:53:00 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:piuaIr798bGRb9lYHvKL8zf/cegLMxDzjDlJG6:b/n98bGblmKYfBPDlE6

Entry address:
0x331C

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 08, A3, 98, 92, 42, 00, E8, A8, 2E, 00, 00, A3, E4, 91, 42, 00, 55, 8D, 44, 24, 34, 68, B4, 02, 00, 00, 50, 55, 68, 90, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, E0, 81, 42, 00, E8, 13, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 01, 2B, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file cyberlink_powerdirector_downloader.exe has been seen being distributed by the following URL.

Remove cyberlink_powerdirector_downloader.exe - Powered by Reason Core Security