photopospro_setup.exe

PowerOfSOftware Ltd.

The application photopospro_setup.exe by PowerOfSOftware has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.afterdawn.com and multiple other hosts a web site host known to distribute potentially unwanted software operated by AfterDawn.
Publisher:
PowerOfSOftware Ltd.  (signed and verified)

MD5:
5e3b8da96a64bfbe4548fd7a2b057196

SHA-1:
66f62e85158699e2543737273e164d386069453d

SHA-256:
1eada4bbba25e1a12de6b681b18df9e9c3305bceecbd175e685b3e489fa2cbbf

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 4:22:12 PM UTC  (today)

Scan engine
Detection
Engine version

Kaspersky
not-a-virus:WebToolbar.NSIS.Agent
14.0.0.3365

Qihoo 360 Security
HEUR/Malware.QVM07.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.PowerOfSOftware.R
14.8.22.23

File size:
46.9 MB (49,168,200 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\photopospro_setup.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/22/2013 4:00:00 PM

Valid to:
12/23/2014 3:59:59 PM

Subject:
CN=PowerOfSOftware Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PowerOfSOftware Ltd., L=Rison Le-Ziyyon, S=ISRAEL, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
410A249080C78CC9486E96E29E654E9B

File PE Metadata
Compilation timestamp:
10/23/2011 3:27:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
786432:RmnyYCgpI4+UgGxnjqX5Fwg1mcEodZO9jL8SODdz7tApyLxeFmBXZvqDX/UrsE1r:AnymBN5Bj45p1F9U9jLwdPBdeQvSPUrZ

Entry address:
0x29452

Entry point:
55, 8B, EC, 6A, FF, 68, 88, C8, 42, 00, 68, E0, 8C, 42, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 38, C1, 42, 00, 33, D2, 8A, D4, 89, 15, 20, 39, 48, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 1C, 39, 48, 00, C1, E1, 08, 03, CA, 89, 0D, 18, 39, 48, 00, C1, E8, 10, A3, 14, 39, 48, 00, 33, F6, 56, E8, E0, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, 33, 14, 00, 00, FF, 15, 0C, C1, 42, 00, A3, 20, 3E, 48, 00, E8...
 
[+]

Entropy:
7.9992

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
171 KB (175,104 bytes)

The file photopospro_setup.exe has been seen being distributed by the following 3 URLs.

http://www.afterdawn.com/software/.../download.cfm?version_id=86606&software_id=3257&mirror_id=0&installer=0&perion=0&air_installer=0

Remove photopospro_setup.exe - Powered by Reason Core Security