freeshortcutremover.exe

Nopumalifo

Huaxinwantong Beijing Technology Ltd

The application freeshortcutremover.exe, “Nopumalifo Setup ” by Huaxinwantong Beijing Technology has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Purek   (signed by Huaxinwantong Beijing Technology Ltd)

Product:
Nopumalifo

Description:
Nopumalifo Setup

Version:
1.4.2.6

MD5:
d5b01809be9e789310a305f22dd03bdf

SHA-1:
d461bfc47886c80e38987511b7a174fcdf6cd055

SHA-256:
50f501f20e7ec43be05e88a6f00067a6cd59002e39b0f854db8620e644bce13a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
1/13/2025 4:04:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.Huaxinwa.Installer.Meta (M)
16.6.30.12

File size:
906.5 KB (928,248 bytes)

Product version:
2.0.9

Copyright:
Fast Software

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\freeshortcutremover.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/24/2016 1:00:00 AM

Valid to:
3/25/2017 12:59:59 AM

Subject:
CN=Huaxinwantong Beijing Technology Ltd, O=Huaxinwantong Beijing Technology Ltd, STREET="Dong Balizhuang 54, Building 2", L=BeiJing, S=BeiJing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C31292C6449E082B3FBF99E310243E2E

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:hti0NiGXIAR5v3nWi+dZKEUQq3p9UdRC+8Y4:hEcbXV/t+dZKEVq5b+81

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file freeshortcutremover.exe has been seen being distributed by the following 18 URLs.

http://www.taggiftflash.com/M4c1kvdIsWDnlnG8xQuJOLc7AHRwn2Rwn5AFdA3_v1 OiYjdmvrXy_ppFoU79bYA4z2IQs g3FP2yPc8FqJel0XqJeD11Swhn6yFdTQgRTB1ONez07ZpsZlGXTDvHYMqWFgQ0pR66LkS6rqkBr0d4i2GDVI7_h0kgHkQynvCnYPQp8 eIYzWBIGHJ9Ude1PIPsISkvHCxkLSmXWFqE0s ts7WU8TcThppGEvXTfasqilh_0okw gON3gtOgdwMluOOF65erHTBdxzCP_qBVcWUVy3EL2Rt1eyqV_DFPbWbarKbdutVGAOge2SF7YmDpfdQhnJdGkvwZteizQnJ8Jr1RkyP6j9Foqhk3IUzWZYGD2XftOMMeIpBfo07riryAPo87I95jxWtNYu99jS9X_VGESHGfGWDdtKDp2Omfny8sHr0BYXvm2B4poTXSCkXX52KoPftJPkXMB7WFEyTJ_PQWyriVyZPDePl0bUIqtdwTMlSGhoIk=-G1cAAMRuOW4sm7LSbtANFkq 3ikHEijVSgK9HezbwWP4PBrFwW_M8RO205WdlDb5ztHVVT30Y1nASdgNdcIH-e

http://www.factorycapitalstock.com/MbDuNml kROIH7hZEkSp3NBOGGWNp5oyvU4YU3tOSbxIlpIl7ybyywOz6iSvNKZVhb68SyQgwRQNtq0UdR_jcWFPbmxIQZZqr9RtgFC4JKTi2OIpUfx 8NpR7JZ_ zdRZuMf8YIMfET_2wS8m_6hrzFTISSf4GXPqEk9HzOKJ2d3oEAZIX87 Zp4o2V27ngNxCpnZTq1OASyPoSzFRdDegw8jn7eJSsMCXWoCL4QRqN E0mzW_2DUAuyL ZOp3TF07rFQTrzJjy8k02SL_tcBfOK5ACOjb lGAF__0H3_0zv_SbqEF2LDk6KfPE8wqVNPZdLo63D3UueUB 538fzDOiWTJW0z6qPL0fIIxqe7WNbxBeObe4jZGMrNjJ5YCM6OqOvUFJ7jXTJvTXCulYnFZMmQ2yinjKyg2mU7tsCHPo10lp_T Nldh01Dy6KxQJtcVcII9cukOwZ1tbEQ2xmI53gnhE0swSIADXJsmyOrkdpyGqRLnY=-G1cAAMRuOW4sm7LSbtANFkq 3ikHEijVSgK9HezbwWP4PBrFwW_M8RO205WdlDb5ztHVVT30Y1nASdgNdcIH-e

http://www.taggiftflash.com/fRAR9PUeXIrrPV7Y6WqgXxGpQBjhGb4 tU23_idUdZBEXub8tz7rIzxS3XlsimfKao ugRrlsuoRS93pb0oSS utNwqbQqhM3ztlf_faDQt3VzTJeVURGGXpnOte GkPMzHQoVXw5AZwV_7sUqCrQo2pPB tG3klj67mWuoWCmTspnjMA9XuVKQBWLTNepYyOn5ZAIVcpnyIqn93fNp yg_LU1cElV9iPAJ j6y8fcDwY80XykWM2WpSRCZJIf az5TgitiLywm2fJ9MaLcSylT0vCI4dkYmYdgqw7SPe6TUTmgavBbgBY4hzRnvoAjgfrRfDrZFbleKn_bnXZLLSdbGKW97ZhoCo99yxVl_u0HHnubDwUmBqZ9cmCTc6IjoZFb tfLLCk7FFWYYU173OpjWbNd4JPgUCklXHnxqxL8vCGnQgzbkh1THTziKBzGdqdVtq6WZkf5gdBvsqk 9pzFwqV1l4WvCAj5Ki NA 2yNUKoTVkw=-G1cAAMRuOW4sm7LSbtANFkq 3ikHEijVSgK9HezbwWP4PBrFwW_M8RO205WdlDb5ztHVVT30Y1nASdgNdcIH-e

Remove freeshortcutremover.exe - Powered by Reason Core Security