touchpad-blocker.exe

Touchpad Blocker

KARPOLAN

The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from dlc2.pconline.com.cn and multiple other hosts.
Publisher:
KARPOLAN

Product:
Touchpad Blocker

Version:
3.0.0.71

MD5:
9dfa39ac4a612cb3e67d2dd7c0c94d0c

SHA-1:
df3f2ed97bc2a6098d5e4af76937bf8aae5f908e

SHA-256:
ebcef118458891350523c6e9995f0d284c085e4f4ce30cadc173aa680e02cce8

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/22/2018 9:25:09 PM UTC  (today)

Scan engine
Detection
Engine version

McAfee Web Gateway
BehavesLike.Win32.Dropper.gc
7.6431

File size:
457.1 KB (468,057 bytes)

Product version:
3.0

Copyright:
Copyright © KARPOLAN

Trademarks:
Touchpad Blocker™, Created just for fun™

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\touchpad-blocker.exe

File PE Metadata
Compilation timestamp:
12/6/2009 5:50:46 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:vdTZZOxi57i7x3JWq/6Xq/thJM/pIp9DpAU:N685O7B/6XWW/pInDr

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file touchpad-blocker.exe has been seen being distributed by the following 9 URLs.

http://dlc2.pconline.com.cn/filedown_64808_7041806/.../touchpad-blocker.exe

http://files.downloadnow.com/s/software/14/50/85/.../touchpad-blocker.exe

http://www.softportal.com/getsoft-22072-touchpad-blocker-2.html

http://www.ranchsendgift.com/5NMr0WbqXx8DPSLEzzDwobYQdm_O7PpsBT9OGMGJVsa2ozWegpAFg6TjRUCSIH8riiICjGkKygq YwyxDj0cVb5UsdD2tte4rEmpsMPwkDZfch3gwnYbIs1CQYD0LATCZ8UyaZQMSFFgBTqx21dSFeZ1wU5YeoOlLez_hcdnu4Od4JqEhSUBicbAuosjPAKZk5z1rDcUDclYexwU xP0EBNZ4QWQXA==-G0EAAES3eX563kMHgpIiBcEGHDgVwaIvNGyMnSMeIeKNK7HThdOiv3r7WQx8ip8LI_wE

http://touchpad-blocker.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/.../hYyuZ22AU5dmk5BK4AbfujJ1AiJTWQuRtVpZ8ONjIrJ uHMYdZIWU32mfy3WTqwwVYxjeXJjoYjyQqanN4Jd3gFqcGDrXoPTzEFU3fuvpNxA==

http://karpolan.com/software/.../touchpad-blocker.exe

https://dw.uptodown.com/dwn/FcJitrr38YnuRpOKHNenM73cwj3V-pBI3oXIU270DLw9L-O2zLi1FmnutDc6GHOuURbkB_1hSAkuEb8XmtKD6VzZaFMyY0SQdGyZvU8--Eah-ll3je3JDu3VuDwvXyrw/kU7OWt6KqPiLjNre16g9ft23c1g5_59vvi85962kl7Dr9HPGbk80Pnbi8yC2D9glnhCKVYlmFOgkzIkT5dE8IoFcg_-qdQvciAODXtRvJgQlRUyIsTjHG1HwSw414UOu/2Xrgo-D6KLe68U8EjlEKqCg_39rPOsHEqtFLx03i5Gjc70Pfl35Hj0FGcWtEK0yN212Zk7HlwCF98hFb9jyIaxeZppsDKT2HahWvaXnW47_Ry8QorCMUDsV9eZeIWo4x/.../

Scan touchpad-blocker.exe - Powered by Reason Core Security