poweriso49.exe

Power Software Ltd

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with Power ISO. The file has been seen being downloaded from software.oldversion.com and multiple other hosts.
Publisher:
Power Software Ltd  (signed and verified)

MD5:
aa000844b20a3aa1f37c0d7458159fd8

SHA-1:
cfd47ee45b7836e9af0a309a6459501f52012e38

SHA-256:
793eb072663b7bb699cfa22b60165e7b6b488b67c0469d98d2bbc865f612794d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 12:17:20 AM UTC  (today)

File size:
1.9 MB (1,946,728 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/28/2011 9:33:03 AM

Valid to:
10/28/2014 8:33:03 AM

Subject:
CN=Power Software Ltd, O=Power Software Ltd, L=香港, S=香港, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11214EC0AA9D4C5C4268811B30352BF16983

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:9VXvI+3irzYpzVkvsAPiL3/ZAUhZw6F95I:9jiz45kvso+vzhZP9G

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file poweriso49.exe has been discovered within the following program.

Power ISO  by Power Software Ltd.
Publisher's description - “PowerISO is a powerful CD / DVD / BD image file processing tool, which allows you to open, extract, burn, create, edit, compress, encrypt, split and convert ISO files, and mount ISO files with internal virtual drive.”
4% remove it
 
Powered by Should I Remove It?

The file poweriso49.exe has been seen being distributed by the following 30 URLs.

http://software.oldversion.com/download.php?f=YTo1OntzOjQ6InRpbWUiO2k6MTQ3OTY1MDg0MDtzOjI6ImlkIjtpOjk3OTI7czo0OiJmaWxlIjtzOjE0OiJQb3dlcklTTzQ5LmV4ZSI7czozOiJ1cmwiO3M6NDU6Imh0dHA6Ly93d3cub2xkdmVyc2lvbi5mci93aW5kb3dzL3Bvd2VyaXNvLTQtOSI7czo0OiJwYXNzIjtzOjMyOiI1ZmUyNDc4MmMwNGE0MzQ4NDFmMjkyNGIxMWM2MjI0YiI7fQ==

ftp://myftp.iiita.ac.in/Softwares/windows/data_burning/.../PowerISO49.exe

http://lb.cdn.m6web.fr/d/c/a/1a4f9a616e93d0d01153420b303df5ee/53202042/soft/.../poweriso_poweriso_4.9_francais_43110.exe

http://software.oldversion.com/download.php?f=YTo1OntzOjQ6InRpbWUiO2k6MTQ3NTYwOTUxMTtzOjI6ImlkIjtpOjk3OTI7czo0OiJmaWxlIjtzOjE0OiJQb3dlcklTTzQ5LmV4ZSI7czozOiJ1cmwiO3M6NDY6Imh0dHA6Ly93d3cub2xkdmVyc2lvbi5jb20vd2luZG93cy9wb3dlcmlzby00LTkiO3M6NDoicGFzcyI7czozMjoiMzI0ZmIwZTQ5MzYwMzQ2MTcyY2Y3YzgyNzRjYWFiMjMiO30=

http://lb.cdn.m6web.fr/d/c/a/435134ed94e27a06920f7730eb893a06/54e78a3a/soft/.../poweriso_poweriso_4.9_francais_43110.exe

http://downloadpt.com/softwares/.../PowerISO_v4.9_master.exe

http://www.software.aat7.com/.../PowerISO49.exe

temp:Power ISO4.9.exe

about:internet

Latest 30 of 30 download URLs

Scan poweriso49.exe - Powered by Reason Core Security