microsoft-powerpoint-2010.exe

Nuboh

SetupSpeedy (Fried Cookie Ltd)

The Fried Cookie installer utilizes the InstallCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application microsoft-powerpoint-2010.exe, “Nuboh Setup ” by SetupSpeedy (Fried Cookie) has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions.
Publisher:
Himamu   (signed by SetupSpeedy (Fried Cookie Ltd))

Product:
Nuboh

Description:
Nuboh Setup

Version:
2.8.5.6

MD5:
e0af37cdf44df43b4b5a7c4b76033bdb

SHA-1:
2e44390059934536b1439e7a0486de6359b5a04f

SHA-256:
ba2827da2680af86aa07befa8b401b5238f6988551b4aba862ad82726be9902c

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2025 10:51:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.FC.Installer (M)
16.5.25.15

File size:
987.2 KB (1,010,928 bytes)

Product version:
4.3.0

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore (using Inno Setup)

Common path:
C:\users\{user}\downloads\microsoft-powerpoint-2010.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
12/17/2015 2:09:36 PM

Valid to:
6/8/2016 5:12:50 PM

Subject:
CN=SetupSpeedy (Fried Cookie Ltd), O=SetupSpeedy (Fried Cookie Ltd), L=Tel Aviv, C=IL

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121EF8B655959B1CFE34F05FAFC8D598305

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:pUZt6QOcfaPBwYnL2csvBxTIqaLaX9cJ62Vu1XuohEkheW:petOcfaPBbnL2csJxTIqay912M1+ieW

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file microsoft-powerpoint-2010.exe has been seen being distributed by the following 50 URLs.

http://www.tourcleantours.com/c?x=bhk891wSQ4zxOh 6t73bypsd7jU7clvoC2ZBSDqKZcw=&c=IXMVCkiRzoOkvp0JW24K0shvp095N4Q8JHzOyy4nRL3SO5U6CJFlE12g3swufEqKIiwaSfUGo/KyJ0L4OmiPJ2QejC5T/Ui1CndcI6WfYpoCMKFXm/nAcPDyUdDQspykym4ZWV8HJU/2X7NyTzGvw3SwaDyO/jtf0I4ZN6wYJCs=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.appssoftwarerepository.com/c?x=kNf2VEx V6HmUHvuWYsysqCOXHC2KFV6jmE0RaYk4jc=&c=YRTlQvDI1gjRf/PjoBT WaNZvvBEsXjUa4kMlIii46IXdvnIBDzvc5 5bP7PzmZ2lXbeT3m5hg1JI5hp8dfODE28GwdtJ8EagE84B5QNNV2Z4G8ImRXl6pU5FYaVM/rp EupmXgXaTzI28t2pme67t80MbwEsZgf6nfdSb6QIOc=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=dGYDQ0o3jpjGv4W2bbVI lG8OqziOWp8lY2K9ZfI43k=&c=GsF8O8f VpRaP8EUJ8ipI4MkGZySfWuKWLbM3FvEO3EYoyWsb2WLXOMv H5NQHdDmXD5FdOcBvxyOxcJKhBl1ju2kPl01sEYr3tQbYFlrv tYE2ncHRaTIqEAvYSbh7 XRlFjMhg2oOnWYmtLj0hRyAZUyCGjLP2fvRJBbGmXKQ=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=eTAkuD /Derl1bPxZfnkx3reP/fRBsJrJ9DIvTdJs0g=&c=EpuBzigsCcYHe5/97L5qKqoFGgxbDbk1azJvv7QvSyPXZzInqV74KA9u1dzviD06iTqZolRQluTik /BNbJ8h ATT09Rf7f8umQBNrvcH/D75FRW434a5 5L0q9bjD1TdHP2CSvdlxFocbmJ05omOJSTM3NHZK VjLXc80EFX/8=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=RP5 JpQrBonA uUysRHfn5iwBUy5yXIW/l4xzLrkBk0=&c=L6V0RWJKnsVhqu1PLKhdizvzvGbBJ M01CPeNJImWlWfeGESpXBi28 ABRGuc0oobuJvpkNmV6VlCZHs3roAqj EDTGSBtllreMXA4G8jlSyOFqPUNOe1PNdzJFWPEdssqyYaSzt9lYppASCT/fqd49hSAgdZSTTCuDCntnVPaY=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=hzwjkBmyd3uTTZ1a6 OGchH7/gkJYtZGsk8XC6MdLNU=&c=7UdCpibUgTkingi2F3MI/LNGtyOW0UkEzU6iWaEgyUZJzRA6aTgA3YOQ1FhVSYkLd8hYTm0qRTCJBOi3jllVFemQ2AgciNJAIzNCN77S7Py59WJAYJ2J/1CxVdTkQSVZVdPDRm4L2iJq5/ihRbMzETb18yq YTbJqBzRtQkHiuw=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=Sd6BSQZpy6Dgr8Ze9w3z4cKx wDwcEiPkDn6ymg3oUc=&c=/BjjjmVa2o0phSDxz ypBybO5G7LIjzrHhAZaJyRNJ9WVs9xxv8d7Quh8dss4UNqwPHVws48rHVx15yW6IuAch3/mz6rQgOdCxVxoH R4Q3fBbA4Q9LN7wajN4X5NzRDb8XUmeZG9d8B3KOb/041Zo B7c5G1iaWjOlhNqioBUA=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/WVl6OTRQV1JwWkZSalFtRlpabk5oVVVkclJuUnlSSGhGVkZCd1RrUTRWVXRWYURKclZURmxPV1ZaYzJVM1dra2xNMFFtWXoxUVoyVTRWR1pZVUhZeE4yNUdSRFZMU1VWNmR6QnJVVkJrZWtFMFVqVTNOMWhrYkRKWFRXODRlbFZyWkc0eFdFMGxNa1pLYVRWMmRXaGxWRWx0VDNWWU4yWllSazF2YVhWNU9FMU5XWEZhUlhGc2VpVXlSbUpSUVV0UmFrUnpNVkZXWW1ZeWJGZHZZbXR3ZVRadGRuVjVKVEpHU1VGU00wbFJjVkZYWjFSRlJFdFlTVmxEVkdjemJGa3pialJtY0dsdU4zQlFWakpQWkdkNU1rRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6UVNVeVJpVXlSbk5sWTNWeVpTNXBibTV2Wkd3dVkyOXRKVEpHU1ZRbE1rWnRhV055YjNOdlpuUXRjRzkzWlhKd2IybHVkQzB5TURFd0xtVjRaU1V6Um5OMEpUTkVMVlI2UW1reGNWQllkRnBwWDBoT2RUUnNUVzEyVVNVeU5tVWxNMFF4TkRZME16UXpPVGM0Sm1SdmQyNXNiMkZrUVhNOWJXbGpjbTl6YjJaMExYQnZkMlZ5Y0c5cGJuUXRNakF4TUM1bGVHVT0=

http://www.centersharenew.com/c?x=PO/srQiON9DGmzIepYjL8GXqcQqiUWCvQ5wTc0pLuFY=&c=DJ2Uov6wrwO/W8eyVga6AAETnE QQuWnOtO6cKKYFJQcIThej905Y3iaEE9Jqq O0cYv1zAt27fg9541HyXd9t MxvhsOsG7dqVZ011bXAsqvddGFGUZiqkWWerlgmdaIz/NoTM46M9bGN7Gkoa0CDXQjXxzHeVhKLe7I0gRcAY=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.centersharenew.com/c?x=8tafNUoZ9CGe2Tye lkH S4DrpSYJUuqWopAYhFONY4=&c=gab/ln5IwB8D1DobSJ JLoSB6vkpe AHZ39fHrmdlC1Z8ZH2AB8jp5sJwGP7EDN5dEgAqH1/J1D6qhE4zzRvJFN13WkpxlmomYJc9pdsUsntAukk2GmJCxfdIT0AUIJjAnAydX47tyX4WlS2rfPjc1vECUkaHc8p985UeN9jQB8=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.appssoftwarerepository.com/c?x=Vr66z5/Lo tUh0grtXq8SiuiCFCaBepIWdHT14NQImU=&c=ct glhL0kpsnuZloQ9yx2Ci/mkoQL0pZDsEhaKjhqs9F0RIoblmCigQNBs3GLPZaSb9Nfg7b2D9G6b36y1pUH3PTyWl65VxkDxlRAc01XpUVivfNoyFqEmy422n4VeKKwW6feNzdjyIPD7Bv9Ms27IuQv6tLlTAQHQyYVCz l6g=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=puQyczjbpdaPWalbOsTv 2V4hZpsQh0k99efLFTcAWI=&c=BtHrczOVL5VmCgVW1ESFddaji VXlRIl00GG4AOIQCF0Rwjs2sIl6piT1vy2hvdvGrzC0Id9nRExSTf/HSUyDCeM6kO9eMucHfgN0VnXNKNZZ1yn98URNj2q9KF9BknIHM1kConPDTkigNn5ubPCHcogK4bzVgrCZLEjWohFitE=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.centersharenew.com/c?x=wFBdiIQBra9MOGCtuPueunp4ex8l9LykNnXjfpD1mwk=&c=Ych2NDxSQVWS72a/H8sdpdRdqyBPEkEjWqa8ogO9aJPAPLcK3FqaQhq8d2Wa09M9xsFSF8Lj BPGwMTL29/d6H VKfjTzhYoTKGemofFA9yFhfzh14YckmWpDm0Luy468bv0NVTGG1v//t5rI0SCNJugs1rIdtH6tNzQTP kJtQ=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=E5Kxn8atOckUPpb4BTgQEEeqsvvjjYXx1D wOxsxrLw=&c=jt7o96mPvWkFU/mdK9Z81PshaG0GbKyC5KBFCTqER/o4BlfommIItMxOlVFAax7q6bd2l3vX9yXEgXJkeWjY1uSf4i5ExTobe8w7foiAA5KXXvR2sRVhvHnMCqL8vz/6UDGXxHtsQMMdKCvB AO5yzlXndQMHRTDtTwJ/z97PUs=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.centersharenew.com/c?x=6wwyp8eUbexqLtBIxEhl0kpu6FMsc0K/Bjsdn5UJNFQ=&c=5vtm6ZY4jM5TTN8msAlT5YXZ67q8K5Lw0BlUkcvMVd2d6F2Fj73IT6QF72IeWeHr3u2qc0fXKYCDOQnwQlloYvwIwNGNfWpBVfOZbLPKnK4JQPEL5tlDx4QYbV0pMkoGs1CuGFf2FQ66nLYsRNcfQ4ydujMWDxNuzVadyxkA4iU=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=lRJr4ru8fsmxDfYN6kFFu9PiHwtzysaBxmmkJTvdFW8=&c=Ldm81GVEudYqkEE5PYRgE4s83Y1Dj0y6fzsonhgL5b8OSwJJy83qMbZq7QEmfWnwvunSBT7OC3cUnzUrTKOXW2llK0rrNtqT9IDct6EWsbn0kUskcMNfllp23eJZgvmE b4J/bOBLcRMu/GmPeUN3TBU1bz/EyoDqET07VTjVrE=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.appssoftwarerepository.com/c?x=KPwmMnGOqkXX0QQLC9p6RdttOjgYKtNxwgnK9GEhrv0=&c=6iRS1fikCFtYOzIEi2TaKWrzPU0lMzt9pUVVl9NN03GfFZYiw9GR6PGZb3p662LJEsiv4XvMPpHN3wZq sguwo5c5jWb dVCQ0yXZh2FfoPO3XEf9ynUZD OUMtbIS2qLXiOcWiuhmLERZSWF5SbgbzuYtWfiM pX2NzxbyvXdE=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=RUcQSz B1hXU62lODp0fbUztYKp W3ZwKBqnbAOO Pw=&c=kZTlg9j3dFVQdk8y5yqWsudasF8t8Ka/EueWp0WO/XrTHGTT0wOQB33oWvF8/QjDtaELq/EetHC9yj8DTSq7GUuu6i948Vuls0QHcPTMvtVMc7qNZiSk9wXWc/6wxNw2pv9nollXGajBkZKv pLZez9pCvLWgn8ad2iBqFkzVwg=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.tourcleantours.com/c?x=GIMtQMV4Y0k9oFDqj/5KYr/upVsUnaHuThuwtrcQZ08=&c=OMsbLVimMSvy4dy6wQqKwxiXPMs5WkPjCVemXOv41Cl8D1IuGfF8EY x24mma3FBV/3Vt3ghlH6ZWMjL2iz4aKZ liosbcsCs2e4IgoNoTAv8uMZyTAh42kMi2ZLfeEsJ5vsarxwyKEsV6QnGVqBNBlr3dc2vD5Cva8sGLm4flk=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

http://www.centersharenew.com/WVl6OTRQVTlQZVZKMVdIcGpkMWQzZDFkdFNHUjRXakEyUWxWd1ZVcDVTM0JWYVdKb1kyUkxlRmxMVjBnMGFsVWxNMFFtWXoxRVNEVTJXbWhTVmpkamRreERiM1EzYTBkV2VrWkZSVTlDZUhOMlpsTm5lak13TkZoWWFIbE5ZWGNsTWtJNFZtcEhXR0ZCYzNnMGFsSTNWRWgwYjBFeE9FNTFKVEpDV1hJMlpUYzFiR2R0YldwaFZWVnBTakpDZW5abmFYcFNOVEJHYmtnMmJHWmtkbkYwWWpkQ2NISk9NbUpKVmxwek1TVXlRbFpUWVdWSVIxbDRTVXBJUkRCcVExTjViM2x2Vlhkd1JEbDJVRFV6ZW1KMGRFRWxNMFFsTTBRbVpUMHdKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndjeVV6UVNVeVJpVXlSbk5sWTNWeVpTNXBibTV2Wkd3dVkyOXRKVEpHU1ZRbE1rWnRhV055YjNOdlpuUXRjRzkzWlhKd2IybHVkQzB5TURFd0xtVjRaU1V6Um5OMEpUTkVTMmswTm5sTFRYTXRSM2RsZERreU5GbzNkelptZHlVeU5tVWxNMFF4TkRZME5UTXdOalE1Sm1SdmQyNXNiMkZrUVhNOWJXbGpjbTl6YjJaMExYQnZkMlZ5Y0c5cGJuUXRNakF4TUM1bGVHVT0=

http://www.tourcleantours.com/c?x=UYH6IbWoFdtJo/KZbfqNKTXbihhL/lLl3GNLF6x/zYc=&c=YU60g3IzPaxNLup ZGCNv1PqTjNkDeY18bQRKNGph6NOX3knMzZ6JMIApMIkKkYqCGC2MNOTihgsruKE7OfFpcw34QcfD0dpvcc8z910Nr8adgL/WamrCuGET2eFc3zJiDsm2BAg4foQ/zh742GmfcuyqRsNMmkRnGgxLqtyqyg=&e=0&fallback_url=https://secure.innodl.com/.../microsoft-powerpoint-2010.exe

Latest 30 of 102 download URLs

Remove microsoft-powerpoint-2010.exe - Powered by Reason Core Security