powersoundeditorfree.exe

Power Sound Editor Free

TechEvolve GMBH

The application powersoundeditorfree.exe, “Power Sound Editor Free Setup ” by TechEvolve GMBH has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.free-sound-editor.com and multiple other hosts.
Publisher:
Copyright© 2005-2014 PowerSE, Inc.   (signed by TechEvolve GMBH)

Product:
Power Sound Editor Free

Description:
Power Sound Editor Free Setup

MD5:
6ba48628275dea5a772adab06505bf1e

SHA-1:
8805dffab2c57d85338862f779fa1cec367fa1cc

SHA-256:
2fc1cb2273d02dc243bcb54da3ab08f0282b8a73de1477fe3a4bfdd5891a2596

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 10:59:28 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Relevant-G [PUP]
151222-1

Bkav FE
W32.HfsAdware
1.3.0.7383

Dr.Web
Trojan.InstallCore.280
9.0.1.05190

ESET NOD32
Win32/Tsingsoft.A potentially unwanted application
7.0.302.0

McAfee
Trojan.Artemis!6BA48628275D
18.0.204.0

Reason Heuristics
PUP.Optional.Installer
15.2.23.15

VIPRE Antivirus
Threat.4786018
46062

File size:
15.3 MB (16,072,840 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\powersoundeditorfree.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/15/2012 4:00:00 PM

Valid to:
12/16/2015 3:59:59 PM

Subject:
CN=TechEvolve GMBH, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TechEvolve GMBH, L=Beijing, S=Beijing, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
50FF3D5C361AE9F52E4B0A3CF576C6EE

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:x0lF+okILR2G+pjkuOUdR3oSYFn3y7rml:xWFxkILR2GWjkuOCR3oSYFn+ml

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file powersoundeditorfree.exe has been seen being distributed by the following 2 URLs.

Remove powersoundeditorfree.exe - Powered by Reason Core Security