sasetup.exe

Screen Anytime

Qi Chen

The application sasetup.exe, “Screen Anytime Setup ” by Qi Chen has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.screen-record.com.
Publisher:
Stepok Image Lab.   (signed by Qi Chen)

Product:
Screen Anytime

Description:
Screen Anytime Setup

MD5:
85342a47794b962bc88a99018f88152c

SHA-1:
f78b1a09995494a96d76f83d756adc22efaf170a

SHA-256:
9e4e5886616ccc6def84023f34fc36ee20398c28db3e18d7d5124a0b6613f747

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/27/2024 5:34:13 PM UTC  (today)

Scan engine
Detection
Engine version

Quick Heal
Trojan.Generic.013526
9.16.14.00

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.12.18

File size:
4.2 MB (4,369,824 bytes)

Copyright:
Copyright © 2007-2014 Stepok Image Lab.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\sasetup.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
5/15/2012 4:04:39 PM

Valid to:
5/17/2014 3:55:41 PM

Subject:
E=info@stepok.net, CN=Qi Chen, L=Leshan, S=Sichuan, C=CN, Description=96gL7431TMF6xOya

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0625

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:oHrJUOw2sWqLQgei21UcU5NI9M+KW7mEBB85oChgdbICS:i9vwbWqLQgFMdsN/+KB4C5GJA

Entry address:
0x9C40

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 86, 94, FF, FF, E8, 8D, A6, FF, FF, E8, 1C, A9, FF, FF, E8, 53, C9, FF, FF, E8, 9A, C9, FF, FF, E8, C9, F2, FF, FF, E8, 30, F4, FF, FF, 33, C0, 55, 68, FC, A2, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, C5, A2, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 96, FE, FF, FF, E8, C9, FA, FF, FF, 8D, 55, F0, 33, C0, E8, 83, CF, FF, FF, 8B, 55, F0, B8, 24, CE, 40, 00, E8, 32, 95, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, 24, CE...
 
[+]

Entropy:
7.9985

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
37 KB (37,888 bytes)

The file sasetup.exe has been seen being distributed by the following URL.

http://www.screen-record.com/.../SASetup.exe

Remove sasetup.exe - Powered by Reason Core Security