setup.exe

Baby Computer Piano

Zhiming Chai

The application setup.exe, “Baby Computer Piano Application” by Zhiming Chai has been detected as a potentially unwanted program by 8 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup.
Publisher:
CFSoft, Inc.  (signed by Zhiming Chai)

Product:
Baby Computer Piano

Description:
Baby Computer Piano Application

Version:
2.52

MD5:
7e532d25940d1e57c1aeedbcec892361

SHA-1:
c498db014d952dbcd7b7445f45b7adb05bcafd89

SHA-256:
42e5a3999fb595a18f889b1e076c6e7bab5405d7134192f9467d93e5990004d5

Scanner detections:
8 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/25/2024 12:27:09 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:InstMonetizer-CA [PUP]
2014.9-161008

Clam AntiVirus
Win.Trojan.Clicker-3867
0.98/21511

ESET NOD32
Win32/InstallMonetizer.AN potentially unwanted
10.13803

Fortinet FortiGate
W32/InstallMonetizer.AH
10/8/2016

K7 AntiVirus
Unwanted-Program
13.234.20236

Kaspersky
not-a-virus:AdWare.Win32.InstallMonster
14.0.0.-523

Microsoft Security Essentials
SoftwareBundler:Win32/Stallmonitz
1.1.12902.0

Qihoo 360 Security
Trojan.Generic
1.0.0.1120

File size:
1.8 MB (1,853,888 bytes)

Product version:
2.52

Copyright:
Copyright (c) CFSoft, Inc. Company

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
11/16/2011 1:43:22 AM

Valid to:
11/15/2013 9:14:44 PM

Subject:
E=ncuchenfeng@gmail.com, CN=Zhiming Chai, L=Nanchang, S=Jiangxi, C=CN, Description=566223-9hK1L2O1nyxQKgrV

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0494

File PE Metadata
Compilation timestamp:
6/18/2009 11:33:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:neZ8KkADBlPMzQ4jX6idfIpCAAzkQWbwrEgL/y:E8KNbsXpNIpCArba1y

Entry address:
0x3121

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 5C, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 3F, 42, 00, E8, A2, 2C, 00, 00, A3, 64, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 24, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 50, 91, 40, 00, 68, 60, 36, 42, 00, E8, 2B, 29, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 19, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove setup.exe - Powered by Reason Core Security