chuzzlesetup-en.exe

PopCap Games

This is a setup program which is used to install the application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
PopCap Games  (signed and verified)

MD5:
ccff206434e0a831c03eda460f275680

SHA-1:
87b9042eabafb8ed5c8b804393846351b41a87af

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 2:53:18 AM UTC  (today)

File size:
7.6 MB (7,995,744 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\chuzzlesetup-en.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/1/2006 8:00:00 AM

Valid to:
9/22/2009 7:59:59 AM

Subject:
CN=PopCap Games, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PopCap Games, L=Seattle, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C61DF38D5BB3836A8B44B985C504479

File PE Metadata
Compilation timestamp:
12/13/2007 4:43:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
196608:WQZkMNHtzePdAbsP5cNRqe2WYHEba95prJev6j0:WQCEHtYrwx1W95iA

Entry address:
0x2D9BE

Entry point:
E8, 04, A1, 00, 00, E9, 16, FE, FF, FF, 3B, 0D, 78, 02, 45, 00, 75, 02, F3, C3, E9, 84, A1, 00, 00, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 80, 3D, 44, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 85, C0, 5F, 89, 45, FC, 5E, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, BC, 31, 44, 00, C9, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 57, 56, 53, 33, FF, 8B, 44, 24, 14, 0B, C0, 7D, 14, 47...
 
[+]

Entropy:
7.9862  (probably packed)

Code size:
264 KB (270,336 bytes)

The file chuzzlesetup-en.exe has been discovered within the following programs.

Lost Treasures of Da Vinci  by GameTop Pte. Ltd.
www.GameTop.com
About 7% of users remove it
Real Dominoes  by Media Contact LLC
Real Dominoes is a casual PC video game distributed through the Game Top download portal. The trial verison of the game includes an icon on the user's desktop 'Online Free Games' which links to a partner portal such as onlinefreegames.com.
9% remove it
Real Poker  by Media Contact LLC
Real Poker is a casual PC video game distributed through the Game Top download portal. The trial verison of the game includes an icon on the user's desktop 'Online Free Games' which links to a partner portal such as onlinefreegames.com.
www.gametop.com/download-free-games/poker
7% remove it
Secrets of the Past Mothers Diary  by GameTop Pte. Ltd.
About 3% of users remove it
Steam Defense  by Media Contact LLC
This is a video game distributed through the Game Top (gametop.com) download portal. The trial verison of the game includes an icon on the user's desktop 'Online Free Games' which links to a partner portals such as onlinefreegames.com.
3% remove it
 
Powered by Should I Remove It?

The file chuzzlesetup-en.exe has been seen being distributed by the following 32 URLs.

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1485520363&Signature=KqU2rEMH7HRI3Q-kr5Od-VsaOuYdlWiZRLgaYvtaz~~aqXrxhCZpJtwhutNm2P2~-X-asIy6G4xm-q8LRr2AWb2GJmxo952U-FQSBiDNtnrkwnYnOSHjDQ4mXg02OehPMH0QefOIGhsJcLTb6DJXL-dU7-Y8cPXqYS37lHwHTBI_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://download.informer.com/.../chuzzlesetup-en.exe

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1453005365&Signature=aUKvOE8IYAfsb9pqmowyHJ3vhA-7DNr1mSKhZ5jPfDfsuKAAPFNF3Iyh2nw~QTXj49uSeC3AL9Y8Jf7mqPzX7QzdlBSqmqdvXPP8Btor7oMMm2XXLYPzWbL2URjOZkwo9vD032pViyOaPI~G6wzFuZs9EARKMahPpCh18MpeWzo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1479936163&Signature=NypsO10~QejQ9XTwUWBoxZE~jMQ-wSaRLbnKoGnsXASo~vIyMmO0Sh4EyguA2RhXar38rHafLeUBCLuJe5w-ZQdIF6lyxAKHsQ91Fwm16BMDPU4YDRJgEJHswLTMsBaSsubpuwqNaUvjjXmj7tKFKKgg-AMK9FULVp75-CUhDec_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1477680423&Signature=VupPc~tzAfxNn5k1evuvKn68UKMOxArbs7KNvobuaGiCoN7YDt1jkhGfXhyN8nphtcJiWvlMR-ZD~N-d9f2WQmrP98VhIRTfHW8zIKxxPhvPTEZi~7~CluGcOoQi1ap0kp2yF4UZ-ZUw-JlSLS1EmkeJ74XCIUVd0GZglC9Og-Q_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://www.capitalvaultsbits.com/8uhGkf4sS8dOgcVhRAdvVlqZadqqE6N8CubqsdCx588oA2L1p4K_M1WkTbz2ObAKDZ1cpELh7EHEXOm9upivojt_2UfNixlsFYGva40rHcO2HlN3gRd4 FBK9pS3l2OGUOcpWQ6bGKYPb3fVXvyIUX25hjKiBfc8MI8BoBkYUCEVmSequ_L5Kp55uAUTUsDrW4WADaD4TmU83OHCX4lWOYejriLB8A==-GysAAMRtbD4dzSmBQVCnE0zkgL2tCA6mbyzjQN6Y MFuQMMS5fvvpHNYLw==

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1444921182&Signature=IWV35P7WbWI2ba9XUSm8THPMLDADYaIxdXyRSb8YGQu~BAin5889Lx2jRGNh0ppAWGENFEY8la0szOW0xoL3kBnA~RgaDAKvSdluz66F4C-OdB4lyFLwlAPGdsiuEGjdkgMOOb9OrtCmnYiaPAxVzLzhxSu5aBQF7b0P-CuMZ6U_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://www.capitalvaultsbits.com/_DXdbRLZut_jJ3A1UsHC0HCuYWVZY71B92 DR2mFZifNbiEOXc5wDzWVZmNzYaCjQL24o3Xj1h9NQnAk0nlpSVcIqUyWgQX6AtgTfP yaTd0MGccIbEHC_PdMq3sXuHow5U1nziaLrQmlbYTEuf3X6hEhtukGXg_QLYhr iFk0_nOnzdktpBsERCwoIfL0zmDmBiQibbmbfz4rsx47GlRu4V56fSyg==-GysAAMRtbD4dzSmBQVCnE0zkgL2tCA6mbyzjQN6Y MFuQMMS5fvvpHNYLw==

http://www.capitalvaultsbits.com/PWlwUoQ7Nnsc_xHK7_r8 mZWu0pNXuXK5qrfOT3t1FzYxNCuTe_P396ne2Cg4Y_erA47G6ELXfmtvZ78DCRonoGmhfsE_6r7ICh5c6oaN2sSYWP81jqPqlP2oMkY0AMsVndYDC2aDUYwjx4Myn OUlfLHUcFQ5ppOHkPQzHGNnt6 0N_oHov7yRwJ37t_CC_F8 fI8oXhacwsXSVpR28mZ78YyNiiw==-GysAAMRtbD4dzSmBQVCnE0zkgL2tCA6mbyzjQN6Y MFuQMMS5fvvpHNYLw==

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1456363704&Signature=CViIoLt6rlkCCsNtXFE8ffXyFT~-X25eSGhEmZZwGpy4IVknnVtwix7Pf6UPk23rUAf7giFNxnr-LRqv4tk4u4CXeGyMjXKKrpEuKA-2stxNLNNIpX93OfPv6udD~8hJnspbHQy5qi3w~PKfx4AW266ZBcv8Ew1gBeUlDMDNeMg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1478330681&Signature=JDklNZn~gCfX6NEkmD92NmC0qYrYsSOgeo86JX1V~GHf0BU1imlaa03SlyQVVyMLYGuDf8mVNoMrH6V4Z4heAf83TuevW~rBBKON-2FLAP1o~r3S1SeOUUllteGBp~1M3epZHFb9QovmJxKdo8i~2ShHuomEzIXvTVh7LenazH4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

http://www.capitalvaultsbits.com/kQy9X2qTGQoGYcLaT XwYz_x 7_0mUwKWXdwOQdQGMXrVId2BUAXYxYrgecypVOENciCNSpmmGjcAgr0ndIhYYeynA02vt3KqyNzLpxKa0M9pxNDz3c8_fqFzYISuXf47OZXsH6KKcHC342cHsDUqw7acTZZYpAqK8NVh1q1lgnqVwqepbHqiliY_0TiqCPpsCyzndu4pjtiHhOJ6J7Ko8rvNFKOcQ==-GysAAMRtbD4dzSmBQVCnE0zkgL2tCA6mbyzjQN6Y MFuQMMS5fvvpHNYLw==

http://gsf-cf.softonic.com/87b/904/.../file?SD_used=0&channel=WEB&fdh=no&id_file=52572&instance=softonic_en&type=PROGRAM&Expires=1449886007&Signature=ZkMWaJBJQyk6pRh2HyVge~wMyzt0kUUv60gbG5-l~fM-W8p~qgxcqxweXWl8J-40lFNy8c5tKwCT1bgevhwsVmzXG4kFLNr~p1IqPt1w6ZthSa1AnTVf-JmtWcPf7IUQ4833TB0YjUOhbQ5691qpSLlHX3DLj0DiNB5N6NgAgeY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=ChuzzleSetup-en.exe

blob:http://sd-web.softonic.com/b5fe4d2a-3900-4ac3-843a-d072767fcc79

Latest 30 of 32 download URLs

Scan chuzzlesetup-en.exe - Powered by Reason Core Security