screencamera_3-1-0-70_en_372678.exe

ScreenCamera

PCWINSOFT SOFTWARE INFORMATICA LTDA - ME

The application screencamera_3-1-0-70_en_372678.exe by PCWINSOFT SOFTWARE INFORMATICAA - ME has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from lb.cdn.m6web.fr.
Publisher:
PCWinSoft Software   (signed by PCWINSOFT SOFTWARE INFORMATICA LTDA - ME)

Product:
ScreenCamera

Version:
3.1.0.70

MD5:
b245aa8f6bec8a0114d1dd1e4aaf4a1a

SHA-1:
71e5be4b0f15e3eae07431f6e617b35cb682dc5a

SHA-256:
82d7c78a1cd98b34e5e4aa8c4f8ef7081fa4f1513bc11e0f74d25f626fa7925b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/23/2024 8:47:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
17.2.14.3

File size:
6.7 MB (7,013,312 bytes)

Product version:
3.1.0.70

Copyright:
Copyright © 2015

Trademarks:
PCWinSoft (tm)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\screencamera_3-1-0-70_en_372678.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
1/15/2015 1:00:00 AM

Valid to:
1/16/2020 12:59:59 AM

Subject:
CN=PCWINSOFT SOFTWARE INFORMATICA LTDA - ME, O=PCWINSOFT SOFTWARE INFORMATICA LTDA - ME, STREET=Rua Fonseca da Costa 59, L=Sao Paulo, S=Sao Paulo, PostalCode=04151-060, C=BR

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F9AEE436ADCE751976B0EF46B9CCA6A7

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file screencamera_3-1-0-70_en_372678.exe has been seen being distributed by the following URL.

http://lb.cdn.m6web.fr/d/c/a/845a4195861f51694bde8447fb93adf5/56bca716/soft/.../screencamera_3-1-0-70_en_372678.exe

Remove screencamera_3-1-0-70_en_372678.exe - Powered by Reason Core Security