powersourcesetup1205.exe

PowerSource

comarch

The application powersourcesetup1205.exe, “PowerSource Setup ” by comarch has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from powersource.comarch.
Publisher:
Comarch   (signed by comarch)

Product:
PowerSource

Description:
PowerSource Setup

Version:
Cezariusz Marek

MD5:
0cfd537876678b52d726152ab7a03c1f

SHA-1:
43f52a3cc64650081068d8d581dd7fe8dc64983e

SHA-256:
49aadf6996c3c31e02ce1e8f8abc2b11abcd1bf8448241430dac76a6cfe5df3b

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 2:53:52 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
Sape.Heur.Aa315!c
2.1.4+

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.5.1

File size:
3.2 MB (3,396,608 bytes)

Product version:
2.6

Copyright:
Comarch

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\powersourcesetup1205.exe

Digital Signature
Signed by:

Authority:
COMARCH

Valid from:
3/4/2014 12:59:08 PM

Valid to:
3/3/2016 12:59:08 PM

Subject:
CN=Cezariusz Marek, OU=Bielsko, OU=people, O=comarch

Issuer:
CN=COMARCH PERSONAL CA, OU=people, O=COMARCH

Serial number:
08B0

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:Sa3WwDS+6jqODvaSumplVNj1ksce1+cRZUwxo:f3zJUqODPplf1PcyRZUv

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file powersourcesetup1205.exe has been seen being distributed by the following URL.

Remove powersourcesetup1205.exe - Powered by Reason Core Security