setup_piano.exe

Baby Computer Piano

Zhiming Chai

The application setup_piano.exe, “Baby Computer Piano Application” by Zhiming Chai has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup.
Publisher:
CFSoft, Inc.  (signed by Zhiming Chai)

Product:
Baby Computer Piano

Description:
Baby Computer Piano Application

Version:
2.63

MD5:
a5b28cad8e85c384e9f1a1e7cac05f70

SHA-1:
7447e555139c23add13713869de705b364aad03b

SHA-256:
85166f70f28d529b144fc9b215b0551cc6d9de168bb6be77dc0d6943fea182b8

Scanner detections:
4 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/24/2024 1:44:26 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:InstMonetizer-AV [PUP]
2014.9-160217

ESET NOD32
Win32/InstallMonetizer.AN potentially unwanted
10.11260

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

Trend Micro House Call
Suspici.5C7004B2
7.2.48

File size:
1.8 MB (1,865,304 bytes)

Product version:
2.63

Copyright:
Copyright (c) CFSoft, Inc. Company

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\setup_piano.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
11/16/2011 5:13:22 AM

Valid to:
11/16/2013 12:44:44 AM

Subject:
E=ncuchenfeng@gmail.com, CN=Zhiming Chai, L=Nanchang, S=Jiangxi, C=CN, Description=566223-9hK1L2O1nyxQKgrV

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0494

File PE Metadata
Compilation timestamp:
6/19/2009 3:03:23 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:djKbVrSMQe4N/nUnHOYO4Vhc2sZ0DkJBWp:YxrPQjJUn3C2sZjJUp

Entry address:
0x3121

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 5C, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 3F, 42, 00, E8, A2, 2C, 00, 00, A3, 64, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 24, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 50, 91, 40, 00, 68, 60, 36, 42, 00, E8, 2B, 29, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 19, 29, 00, 00...
 
[+]

Entropy:
7.9859

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove setup_piano.exe - Powered by Reason Core Security