camstudio.exe

SpeedyInstall (Alpha Criteria Ltd.)

The application camstudio.exe by SpeedyInstall (Alpha Criteria) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.conceptspresentmeta.com.
Publisher:
CamStudio  (signed by SpeedyInstall (Alpha Criteria Ltd.))

Product:
CamStudio

Version:
2.0.5.a0.1_63980

MD5:
3e9e00232607071c21f734244d217286

SHA-1:
734c72e8fbbb2448e5b0d4deea920ed885bc0ea6

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/28/2024 6:53:36 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.AC (M)
16.8.6.10

File size:
1.6 MB (1,640,088 bytes)

Product version:
2.0.5.a0.1_63980

Copyright:
CamStudio

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Common path:
C:\documents and settings\flont kazimierz\pulpit\camstudio.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/6/2016 4:35:52 PM

Valid to:
8/20/2016 4:45:01 PM

Subject:
CN=SpeedyInstall (Alpha Criteria Ltd.), O=SpeedyInstall (Alpha Criteria Ltd.), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A6DC69485443ADA37B28455486E38F93

File PE Metadata
Compilation timestamp:
10/13/2013 10:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:XElbYOS5l07fR0j/tHeByNcdHzhsq9rS7hkd:uMqZ0TtHuyubsB9kd

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file camstudio.exe has been seen being distributed by the following URL.

http://www.conceptspresentmeta.com/c?x=KsOaL3vLw24QHxHTbA3yWJ/g1vIT4pjOeEFpzQFAmFA=&c=S wze0VDFPszuC3M4mFRLghYQKmoH91uARh4S28lVvOvH3kvzVPVU4GDKx39QaxEQgnj8V23i3gKQbd7kb2bh2nZfDIofJio10xWl5gjffXyVcBtSkVO6w/YAkpLn3Qju0djx1cMoaHC2yODJa50B5yQJiikF9/G45yZV4bY194=&e=0&downloadAs=camstudio.exe&fallback_url=http://.../CamStudioSetup.exe

Remove camstudio.exe - Powered by Reason Core Security