debutsetup.exe

Debut

NCH Software

This is a self-extracting archive and installer. This is installed with Debut Video Capture Software. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
NCH Software  (signed and verified)

Product:
Debut

Description:
Debut Video Capture Software

Version:
1.90IT

MD5:
4f9a14aeb8b3eff48933c74a826578d3

SHA-1:
b4ec40411a720ed6b4050c8e6c3489c2b29734ff

SHA-256:
7d62c65edd81caa181012f2ca324a4aa6fb27e45e152b60503cabfae6d7b458e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:45:58 PM UTC  (today)

File size:
1.5 MB (1,533,464 bytes)

Copyright:
NCH Software

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\users\{user}\downloads\debutsetup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/20/2013 2:00:00 AM

Valid to:
8/8/2015 1:59:59 AM

Subject:
CN=NCH Software, O=NCH Software, L=Canberra, S=Australian Capital Territory, C=AU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6A560820FA3E9AD8E5411734B1D40AD5

File PE Metadata
Compilation timestamp:
12/10/2013 6:05:55 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:4MH02LliKVKjf77+oZzGKSaAsGqESA19vDYdLuNx3bhgX4Hk9NJYuZ9o9S2DdpI7:jHVUcKjXJQ0ESA1BYRQhhg7NquUXDT2

Entry address:
0x21D8

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, FC, 16, 00, 00, 53, 56, 57, E8, 03, FF, FF, FF, 33, DB, 3B, C3, 89, 44, 24, 14, 0F, 85, DF, 03, 00, 00, 6A, 06, 53, FF, 15, 88, 10, 40, 00, FF, 15, 4C, 10, 40, 00, 68, 6C, 14, 40, 00, 8B, F0, E8, CB, 03, 00, 00, 85, C0, 74, 10, 68, 7C, 14, 40, 00, 68, 80, 14, 40, 00, FF, 15, 00, 10, 40, 00, 68, 90, 14, 40, 00, 8B, C6, E8, AB, 03, 00, 00, 3B, C3, 74, 49, 83, C0, 0E, EB, 08, 66, 83, F9, 20, 75, 0A, 40, 40, 0F, B7, 08, 66, 3B, CB, 75, F0, 0F, B7, 08, 33, F6, 66, 3B, CB, 74, 20...
 
[+]

Developed / compiled with:
Microsoft Visual C++

The file debutsetup.exe has been discovered within the following program.

Debut Video Capture Software  by NCH Software
During installation the program will offer the user to install the NCH Toolbar, an ad-supported web browser toolbar.
www.nch.com.au/index.html
20% remove it
 
Powered by Should I Remove It?

The file debutsetup.exe has been seen being distributed by the following 18 URLs.

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1476154253&Signature=EJSP53XOqDrj8vDQm0ReWheDbBoVSkj6TxKCElhD35ddEylH-Tjyne331rCTiZF68Nte7IfGSCpaFtI1a6ZYVuVg03afLCnwd2cMoFOo03QZRprZZ82S4FBO1E8e9dtnJhn0~FnbOmwBelPqxSyJQoLvK25HqVehjZscFYxFo2U_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1463953772&Signature=WjDgIoEShMjK6eTUdKZbnw1~mYV~6jY8U5FBXVGkGgDVW36ufYHfFbUuTqyQOHkGlybAlCE7-dGBCNZ3ffppBYZffeNtk41Gjyprsk0KXboPMhVKY8fVWIIh~2QxLE54-Jvy4GKDACnda~PiZ-IMp6YBzomhkS5nYB2UhA8vX48_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1477191639&Signature=EuYAQ1FPR6ke8FqAE9pdTs8SwgUVk1RI~88cowSl3hYAwC-n4dN0R2qTxQPS2F145KW50sTF~SRG0~6v6J0fVuqqSUQ9Nk3K3vAPBs~6tz14xTah8Wl-zkRlN69BEoCO78WNLdEagq-cCkH192RLEEw7k8iYMFdueiQunca8q7Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1452037064&Signature=B0M1LGI-dOAdHvt3f-1hp7w5y3ulxLU9EN4C-03hbdlx381j250q88xquRFQ--8BOP-B90b4dC-9h8lsQPuI8ANIAKsXcApgllxNSj1v4lnU7vde~vTRRNCwrLxisw~JZVM0o6vsQbgPpnqwU1-rxi2f6Dowo9vTLSYbw17fhEA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1456884430&Signature=XxejHSgW2fr8XuiHrLuDqkirnlUMQxehkRXf~hPEcH3hJ5xVUEbrReqqB8fi5UFsNXaMHQq2ApbyXN~r9-z6BnBCh8O~L-vX1wFm1UKWPjlQtn7zA95Neskp-aKEuUtb0DJZX3owSE-nROfOW7AgAIqfZ1PopCViIPqKW04JqC8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1473123785&Signature=aRN6-NE3GqGaFOWZaOjBL6361u7ZieQTEazknIG1vKj39AGyiHkaUYmkIJ3ShgD1NjLwdLHEdZ7CF~Sae-XJaYjhO5FvqisNNVkJqV3rCAFGWaBQj~~6vABWkJ5QNv-IJijRBwAB7PHmwuo8z5PA44X0N2UXpXbnGSlnFCvl4l0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1475979649&Signature=ZxsJXlPRLnx2PQ3c7KTA87Ng91PUuK~7oanX6QRCOsiBNXnltRAdJhVRD0izGAoi-h24VyZv2BSkBsKYyz7hX7cMUldWUo0Jknwlp7mz6rXmyO4P0FlTUxxpZ1bo2dOfY3l-UjbDOMloiN31DNHt6nCeZTV6zeIRDNpqEVu6ZDc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1476232941&Signature=Myq0akevaNiRqHRPblIjdwsBY9uYxHQY9OqllPm0Rg9d62yJzU-zGkEtYZJkxJM1DqIXc2ZtBjTGQsIzkAwtcooxHXysq2P5raL6PNZCNjLezaO4TiecwQJzIw4kLuM--OE-F-GL~8tFQ05aQ~YJifsfjJgNDJH8~hhsDhAo620_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1478489125&Signature=f644HjcWrHg~QA7SK~98D8RhlaIZZtOH7k7UWTaJMaNBRzMJo7lKOKft3xqtPsf5Yt6oDPgLg2r12r6lw3RMoaR36v6gOzCH98CNINQ-gosTy~s1sbfqbJKlpApEv5Q54Y4W8a5y1r8PV2XFZ8g7I3yVmokssvaOcGZ2ZZtarQ4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

http://gsf-cf.softonic.com/b4e/c40/.../file?SD_used=0&channel=WEB&fdh=no&id_file=64806&instance=softonic_it&type=PROGRAM&Expires=1461264056&Signature=H1wrpZct38inWevZKNz79zhS3N~44lA8OXWoly5P8MGMMd8oxWaM7ydBuMrGqlnI1~MuT0ps99dGEqesxMd8MUhURCckD-pNnOjskdxORcC824XYr0XmEx64cYEOLE1thiNxcH2eXZTNou-TpTPcsWGq9d~-qq7TS5FhQWo4MgY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=debutsetupIT.exe

Scan debutsetup.exe - Powered by Reason Core Security