photoscape_setup.exe

Creative Internet Ltd

The application photoscape_setup.exe by Creative Internet has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from download.creativeinstaller.com.
Publisher:
Creative Internet Ltd  (signed and verified)

MD5:
79bd3ab27ab3376a4f03552da447f931

SHA-1:
94d3802f9dd166363250c8ff01ebff8ef2e76205

SHA-256:
79ccc7a806dc10721af76ba62bec7724cf6913bccfa8aead18f4f7e4fb665152

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/24/2024 1:24:22 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.InstallCore.133
9.0.1.05190

ESET NOD32
Win32/InstallCore.DJ potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.InstallCore.ENG (M)
16.4.20.9

VIPRE Antivirus
Threat.4150696
48758

File size:
624.5 KB (639,496 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\photoscape_setup.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/14/2013 7:00:00 PM

Valid to:
8/15/2014 6:59:59 PM

Subject:
CN=Creative Internet Ltd, O=Creative Internet Ltd, STREET=64 SOUTHWARK BRIDGE ROAD, L=SOUTHWARK, S=London, PostalCode=SE1 0AS, C=GB

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B0260B1A6AF7BB022FE065132251B61D

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:4oMJfsGN9wy8sxzin+yAcJJgq0ydbkA5Ew4LlKVJaEdjQB0dL9X+upd:fMJfsAGy8uin+DcJW7yJQlGwF0t9X

Entry address:
0x98CC

Entry point:
55, 8B, EC, 83, C4, CC, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, FA, 97, FF, FF, E8, 01, AA, FF, FF, E8, 2C, CC, FF, FF, E8, 73, CC, FF, FF, E8, 0A, F3, FF, FF, E8, 71, F4, FF, FF, 33, C0, 55, 68, 76, 9F, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 2C, 9F, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, B0, 40, 00, E8, 9B, FE, FF, FF, E8, 26, FA, FF, FF, 8D, 55, F0, 33, C0, E8, E0, D0, FF, FF, 8B, 55, F0, B8, D8, BD, 40, 00, E8, AB, 98, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, D8, BD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.8269

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36 KB (36,864 bytes)

The file photoscape_setup.exe has been seen being distributed by the following URL.

Remove photoscape_setup.exe - Powered by Reason Core Security