setup_screen.exe

Splendid Desktop Helper

Zhiming Chai

The application setup_screen.exe, “Splendid Desktop Helper Application” by Zhiming Chai has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The installer uses the InstallMonetizer platform which will donwload and install adware toolbars and other potentially unwanted software offers during setup.
Publisher:
CFSoft, Inc.  (signed by Zhiming Chai)

Product:
Splendid Desktop Helper

Description:
Splendid Desktop Helper Application

Version:
1.59

MD5:
b53fcd360edd6e1b4c73014f79018060

SHA-1:
0e5adccecb639cb11f18436127570b40e9c5b4c8

SHA-256:
821339f703683363a3902ed5860356823bfd2168a639b39b8fb1f27642165589

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallMonetizer distribution platform to bundle adware.

Analysis date:
4/25/2024 4:44:12 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:InstMonetizer-AU [PUP]
2014.9-160214

ESET NOD32
Win32/InstallMonetizer.AN
10.10360

Qihoo 360 Security
Trojan.Generic
1.0.0.1015

File size:
742.2 KB (760,024 bytes)

Product version:
1.59

Copyright:
Copyright (c) CFSoft, Inc. Company

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\cfsoft\screen.eng\setup_screen.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
11/15/2011 8:43:22 PM

Valid to:
11/15/2013 4:14:44 PM

Subject:
E=ncuchenfeng@gmail.com, CN=Zhiming Chai, L=Nanchang, S=Jiangxi, C=CN, Description=566223-9hK1L2O1nyxQKgrV

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0494

File PE Metadata
Compilation timestamp:
6/18/2009 6:33:23 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:rM6gr6gr3ddddCdddkwJg04gggguggg0YwvD7jxLupjDxGMpBBW/0doqK77DVR8R:rMZN3ddddCdddkurYcD7jBQ/bB1doxQB

Entry address:
0x3121

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 5C, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 3F, 42, 00, E8, A2, 2C, 00, 00, A3, 64, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 24, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 50, 91, 40, 00, 68, 60, 36, 42, 00, E8, 2B, 29, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 19, 29, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove setup_screen.exe - Powered by Reason Core Security