powersoundeditorfree.exe

Power Sound Editor Free

Beijing Tsing Software Chuang Xiang Information Technology Ltd.

The application powersoundeditorfree.exe, “Power Sound Editor Free Setup ” by Beijing Tsing Software Chuang Xiang Information Technology has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The file has been seen being downloaded from www.taggiftflash.com and multiple other hosts.
Publisher:
Copyright© 2005-2014 PowerSE, Inc.   (signed by Beijing Tsing Software Chuang Xiang Information Technology Ltd.)

Product:
Power Sound Editor Free

Description:
Power Sound Editor Free Setup

MD5:
6057a1d0e6be56ca6d6c901c6faa1d9e

SHA-1:
feb618dbf5e71075a7ebc9dd8e2af44c9e216518

SHA-256:
27dbbfbf0be7bca896f4bdd4ac09d7f0c15f07c5f5bc135041057ef853e48fbd

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 12:52:09 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:Relevant-G [PUP]
2014.9-151001

ESET NOD32
Win32/BundleLoader.C potentially unwanted (variant)
9.12239

Reason Heuristics
PUP.Bundler.BeijingT.Installer.Meta (M)
16.7.8.10

File size:
15.4 MB (16,103,264 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\powersoundeditorfree.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
6/8/2015 8:00:00 PM

Valid to:
6/8/2016 7:59:59 PM

Subject:
CN=Beijing Tsing Software Chuang Xiang Information Technology Ltd., OU=Tsing Software, O=Beijing Tsing Software Chuang Xiang Information Technology Ltd., STREET="1901 Moma Plaza, No. 199 ChaoYang North Rd", L=ChaoYang District, S=Beijing, PostalCode=100025, C=CN

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2499674FEF00F9742694DBD0BA0ED373

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:XPggaWgXgO+4pgqlDsFBooULRfuckLDWspjv0iJIBqqgmYfDAxwxQcnZiHJyyFRN:f0lF+okILRucYlFFIBqHkwDQpyyLGSZ

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file powersoundeditorfree.exe has been seen being distributed by the following 22 URLs.

http://www.taggiftflash.com/WVl6OTRQVGM0ZDBZMk5GaGhWbVU1V1hWV1kxZDNNSEpTUlhOSmIyeHJUVlZWY0VKTmQxUjRkRVZvTlRZMlFtY2xNMFFtWXoxVVkyaHNUak5WZUhSUFFsTnJNV1V5ZDNOQlFuTnpTRFpOUjJGWVJVdHFKVEpHUjBoSmEyZzBNa2g1SlRKR2VVRXlRakZ1U0ZCR1dqSk1XbkpETjFSdGIzQlViMlo1ZWtscFZFOUZWR1l5U1hSUWNWUnFZbnBIVldwbVNEQlRVVmh2VWt0WGRuTjRWbXhCYm1jeGF6QlliRmRDTWxFMWJ6WkJaa1VsTWtJMlMwMUhiMmRTTjJKM1FYTmxWMWx6WjB4VFJsZFpWM3BqUkVjNVdXY2xNMFFsTTBRbVpUMHdKbVJ2ZDI1c2IyRmtRWE05VUc5M1pYSlRiM1Z1WkVWa2FYUnZja1p5WldVdVpYaGxKbVpoYkd4aVlXTnJYM1Z5YkQxb2RIUndKVE5CSlRKR0pUSkdkM2QzTG1aeVpXVXRjMjkxYm1RdFpXUnBkRzl5TG1OdmJTVXlSbVpwYkdWelpHOTNibXh2WVdRbE1rWlFiM2RsY2xOdmRXNWtSV1JwZEc5eVJuSmxaVjlKVXk1bGVHVT0=

http://www.vaulttourquick.com/OHZ4skOiPAk8MOkBDTefxOq dfvqGgEhI4cNQ 3a5P0vLMKJBSoos3AhyolIGpzu0vbhHHFx4simrxbSY1l1DtxQ2XC7tt0FC48pyHXomrawr3oxe6HhzHgUZi8udQ84b5dp8AvuIDvpWHHhtV3XmSv1J63IFIBgmdLbSR2RkIaC0PUdWVtCYfJ7g0nafOuZ7k9XZUYGqfLF0VOzieE83 h wgVZy NPZFPKBaEfLfT2ilM unE3kCN1jBRY0Lh8fRwniFFjEE Y0_2hFuN5DQ9fhQFUAjWxTr40xmViOP GneguUU_0gJ6rWWKjBQlz2fMk0CbS uDNiS gutX8HVRfufWua39mpXhtzNmW_Y2bXmdMBZWMDS7ah8A7GMriiF3xxPcYJ4hj4ntQYgIzEJX0Fnzuni3NLQ4dhSc6VxidoaAWbSxtZ7OfXD3FgSn7bQgRw64vXDLdx76X oU KDKMwUfpzfo99b2OzcI3IW8lpIcr4wDCfGVadpg7HNYOcEO0l1LI-G0kAAARqckhfQrXFP48OJMpTFnJnBDzUck9ZESobhPfrGmN8sFXMKSyLsat9Lp90i3UtfH2w4 AB-e

http://www.vaulttourquick.com/rL5CjnIRr7fx1LHcIxf_xfG62hilDog01BAbQis07nHwqjwEdaOJ0oiOv27lxEugn56l2wnCMOJzcHlSugU62JHc6j34bETtHiE4J5Py6DKkaJHIFBVHVjpLXtaZqaRWlKKrMMvvx1vMFG2MjZvbdt6afJ4pG98 fdBwtATWKNh4AHgid6pOIuzuaWC0_eDf02qrxzjrJRUmBeO3lBqNaZnI66zZ_RyM3zaZPGBymbV i45WGNEPzSqGqMIkS7fakfgdkEDx3QE1S3_X 5o9dw2SbajQZE158PiGs6Y5_h9FhawZerfayw9kdZT MPP3B4jefUQ6KJA pYNat5mUJxAcwXCmKX0WmdqBEwWAQuFdp1heYGD9aSO6Q1qSGifj5LhX6uslL ja38Cc4ox58QGpoORrCygjXgYWmcc1EU2XL1zpWMTMAZFU3bcMUGa_IozAa9pwUUW3xkZJcFAUc_cXyfbNhRzBMaFRSl j3kewHE0i68BgCeIunQ0reVkfzvkVq6gV-G0kAAARqckhfQrXFP48OJMpTFnJnBDzUck9ZESobhPfrGmN8sFXMKSyLsat9Lp90i3UtfH2w4 AB-e

http://www.free-sound-editor.com/PowerSoundEditorFree.exe

http://www.taggiftflash.com/c?x=9ZtPDqt5pyFBamm2r b 5ml3PZHfzS8sNeubQBlTskU=&c=exgfIooH1Tl9C1TQSmOLVB8OUV4KkcFW3JmNMxSqhMCv/roLRL7LlbJPAs9oMkGHJI6PSEazdEkUTk8ZpqxkLBEIoeW2uM4FCKMNVsVhYsJDjN6vUC9EwQgGzX3dttd7Z7iJTUV/TEIchmN7v73egqLqFyZaesSfEFMWzb4MCFqwD0eGEEr1Tij3BmPQ1YGd&e=0&downloadAs=PowerSoundEditorFree.exe&fallback_url=http://www.free-sound-editor.com/.../PowerSoundEditorFree_IS.exe

http://www.laboratorygrabtower.com/WVl6OTRQVmRYU0RsV1dFeEJaVUZLTjBwWVoxaGpjamxTYm10R1drRlJhQ1V5UWtGalNEaHNVRzAxT0VNNVJ6bEdZeVV6UkNaalBUbG9RVXBOSlRKR1kzQkpVME5EZVdReGJWZFFOVmRJV2tOclVIaEtVemh6WmxwS09VZFNXV3BNVkVnMWJXTTBOVTFLUVhOcllVNVhaakJ5TjJsd1J6Rm1TeVV5UmtOb1JsaFpjMmRvWVZOb1drTjVkemxrUzNobGRHSlpha1pRZFVKR1kyeDJUbGc1VGxGb2VFVnNXa3RXVjAxemNFZEpTMjFUWmlVeVFqZE9XSEZCUjBWaEptUnZkMjVzYjJGa1FYTTlVRzkzWlhKVGIzVnVaRVZrYVhSdmNrWnlaV1V1WlhobEptWmhiR3hpWVdOclgzVnliRDFvZEhSd0pUTkJKVEpHSlRKR2QzZDNMbVp5WldVdGMyOTFibVF0WldScGRHOXlMbU52YlNVeVJtWnBiR1Z6Wkc5M2JteHZZV1FsTWtaUWIzZGxjbE52ZFc1a1JXUnBkRzl5Um5KbFpWOUpVeTVsZUdVPQ==

http://www.applicationmegavault.com/rBm2KzzQ mnWPxP2GJJNuGHxpAF_EXUd9XJZyq42WhYWrHcgfeYXrAIGr6qYlPQfeTjGzpjAHoLkLxbDNqt577L70e8EJKRx8LOrIaLIkkjchcWlZy_44M_zbxK1P4WsKceB0FkCp6Fzn2c35jx79aGrZPuzMADJiSPD54Gln1bjtyeCKs1f5tXWU_ZScsXvvBX2gJUmAt9e1Hz_RKfQa1R2iZFXm8HEBGdj GqfdpPTdrq2uQPEwWwkfGdoU75lzuSsK4m9qfm9dF05R9JxD0bzh3H4bq9188DUN tO534k9zZ4x6K4kWSE5zX1nau tLV70RUmKWomQ3XA9Tr284QrnFp2IxS90lk1lAHPyYwBVkGWfFEdD2ZnyflyKUVo5YegTFPodx9V1FjiCwnUXVI3A6EtzHNS3dES1xWL2CN9JRnnRJkv_4WsFjn3j07gSunR8_N5pbXaV 8YHx29z8HCiQYh7CDMpY5WsHqwEXgijUeO3t2X5diT0kt9_bra9EYkNUCF-G0kAAARqckhfQrXFP48OJMpTFnJnBDzUck9ZESobhPfrGmN8sFXMKSyLsat9Lp90i3UtfH2w4 AB

http://www.applicationmegavault.com/YwDUcA2cizXj6cphgfsEO7JfmULmS_eNcLxhlV33F xdOtaZy0BiDYNihIkKZidVwVfp_zj_OSlrg4ZfGRuUVvmhTLnxOm8wlz4Hb9wXeQl5tQ38gT 801d4gNpYyz_EKc4ZDIuF6LshYosw9wRsQm3Acy 2Pv3SfIJhrprsAKN8UKeL8irBjUA76K0Y1PqGuu_hxESgFwN1iZWdYJg0DaQWu3X21S1q4PiP 56OnkKwkv6knXxJqQqmizcLEyUaidGS56PT9pLz7oI1wrHUD4fs_hCO8pxjTDhhcEkoOzWaqM8aKuRLS6TQCdmN0nrekbFny9_J3KCkcWpp6kXbdGrrlUqKEnZMKkxyarFkwHaLtu3dEi4ZCZ_pUO0FMlbNYXDIOoCPhXpdud v22jTNIFBcgiWlrS73icQ6baSsU5V2hmnvTLu9T0rR0wVp0zW34hNMyYrrEEp4jluuuLWiofQ5oWW_k5TvzwpN4INywO9rpRFU3IySwXGbXFntpzBGNCICzZa-G0kAAARqckhfQrXFP48OJMpTFnJnBDzUck9ZESobhPfrGmN8sFXMKSyLsat9Lp90i3UtfH2w4 AB-e

http://www.applicationmegavault.com/qE_1Y57moRadjRWLm JNWGYcjPo6kPlEx08CrNNpoYVXI uQn6e0xnl7gYJKWXeoVtzP4X4Xue88cuxKkBH6pkUM1sixLGnc33j5F7pdsCTL4B_U260QTrSV1Lha07ymyTR75pw63Hy5KmVcEJZRk kjVg4GnGJda0a98vvP wSvSlYrP7azetZztXsyAQ_6hYxt4kmGeVqqCE73ZAEpJhxXYLdAIQ==-G0kAAARqckhfQrXFP48OJMpTFnJnBDzUck9ZESobhPfrGmN8sFXMKSyLsat9Lp90i3UtfH2w4 AB

Remove powersoundeditorfree.exe - Powered by Reason Core Security