dpfsetup.exe

Duplicate Photo Finder

Ashisoft

The application dpfsetup.exe, “Duplicate Photo Finder Setup ” by Ashisoft has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.ashisoft.com.
Publisher:
Ashisoft   (signed by Ashisoft)

Product:
Duplicate Photo Finder

Description:
Duplicate Photo Finder Setup

MD5:
d0374dbf7523a860672cc724ee40df98

SHA-1:
28473bceaeca76eab4f91e0a97d99f9b6cedb8e1

SHA-256:
07edab0fed945d4f38b1e9028ee3e1698f84e361f03b9f2917cbbd9500961a53

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
5/3/2024 1:49:54 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.1.22.20

File size:
686.8 KB (703,304 bytes)

Product version:
1.2

Copyright:
Ashisoft all rights reserved.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\dpfsetup.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/1/2015 8:00:00 PM

Valid to:
7/1/2018 7:59:59 PM

Subject:
CN=Ashisoft, O=Ashisoft, STREET=11-4-613/1 A.C Guards, L=Hyderabad, S=Telangana, PostalCode=500004, C=IN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2E75AB8C56060A2609D1FE37697C89BC

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xAA98

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 2E, 86, FF, FF, E8, 35, 98, FF, FF, E8, 9C, 9B, FF, FF, E8, B7, 9F, FF, FF, E8, 56, BF, FF, FF, E8, ED, E8, FF, FF, E8, 54, EA, FF, FF, 33, C0, 55, 68, 69, B1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 32, B1, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, D0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, C2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, 24, 93, FF, FF, 8D, 55, F0, 33, C0, E8, 66, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9647

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
40.5 KB (41,472 bytes)

The file dpfsetup.exe has been seen being distributed by the following URL.

http://www.ashisoft.com/.../dpfsetup.exe

Remove dpfsetup.exe - Powered by Reason Core Security