setup_funny_photo_maker.exe

Funny Photo Maker

AnvSoft Co., Ltd.

The application setup_funny_photo_maker.exe, “Funny Photo Maker Setup ” by AnvSoft Co. has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Funny-Photo-Maker.com   (signed by AnvSoft Co., Ltd.)

Product:
Funny Photo Maker

Description:
Funny Photo Maker Setup

Version:
2.4.2

MD5:
fb0ceb090b8c78b87a80d119fe85fb2b

SHA-1:
a4dde3b5f3910d4063877331d810e36745c6b0e3

SHA-256:
2b5853f9e57bcf1157798d0fcee1568153c18da363d35698318446104752df59

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/26/2024 1:37:12 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
8.9715

Reason Heuristics
PUP.OpenCandy.Installer (L)
16.11.29.21

File size:
48.3 MB (50,668,184 bytes)

Product version:
2.4.2

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\setup_funny_photo_maker.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/15/2012 3:00:00 AM

Valid to:
8/15/2014 2:59:59 AM

Subject:
CN="AnvSoft Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="AnvSoft Co., Ltd.", L=Shenzhen, S=Guang Dong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
765E3E079F21928954D8BEC66D023B52

File PE Metadata
Compilation timestamp:
10/13/2013 11:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:yY1LSFCU7WZ5+aS8HcYzYO96h/qLNhApOKsLeQL14kW+9loX:ynxq7+u8Yz0hy0pOKrQL6k8

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9997

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file setup_funny_photo_maker.exe has been seen being distributed by the following 50 URLs.

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_fr&type=PROGRAM&Expires=1429061146&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Egsgg5WIM0TrVIjiuhOpXFxmvMBsuqtXPRNj8C2Eh7pcQyYMVFopAYaOCMRfEIVKjM3ECF3Muod39VzRrRjkJ0VWlUn3bwq6c-M-xCqWxnQAm2Mvj15w6IOzykocCP5-sQq27zdmwUpb4ITEx1aclRki1OL3Sdv4Xrk1Om9ydSw_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_it&type=PROGRAM&Expires=1483124759&Signature=IWIy8QGCEh0XIV-Ntj-X9APe3oqZdm2QktlvAEa~c8A2Duh3LGloTDMPUY0kizgeF-3SzFQ5z2VSXUxhklxOwOPH76no--BqM1qvui9xMrYLx6oGNBPUGIPteFTR3RejBNCnYu6aLOGfLdKHtuibElFhecUh~kzyXlVX7lfHoi4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1427826650&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=gRho51EmYiN9QajXwDj~x7nj6MZbiyXENkDolGpJsXUtbvSxxPhgJCkNc86ZULbO8~hjni14rLbG944d5~u-onqG1NW6ad7qnVwGTlTg2K7Y1HgLnjszKqQ2wL2EdsOv01q8~iTjf-86TWZyam1E1VtYpFY2Xxi6wc8rx8ZcTCo_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1429408503&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Ji1dV6ZQL7mJw~cAMcr~LlI3Ak2wqacNKU266rrcjp6OqnnawZb4eP79VEuoJRIZyYPHoEku~FtbB4QHICRjXunkeYJlUqB3XZI~x6l9T-AkN4taFvVX8o~1Iw5At6OoLSJv-K2HbdaYR5wMDP4cgQ1zAt5uWNCo7E44RVJisfM_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_fr&type=PROGRAM&Expires=1484032754&Signature=ZedYfYs2vMZoJ~XkJOAf2o8MiFpsFqMLNlhiZwCI7SPUTmwzD9tfJUX9~JCgKxwtOP5ypA~rnC1hz8qwBa3bVGwBpsppjOfE1LnajN8zMx7e1vLGbQXRqnh019OsrycThu1xhxOS7tg8YtcQOGV1gAALUleyn~quQIt3oLhe120_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1476358445&Signature=S3DrdZJ4fRuUXvSqPJviIQYT-FnM41nFosYoaCx2yaY20i0DUYXo0H4msHqqE8dubHLZXd4lDHmrNNvpkPUakgG43Kn4t~~ieLAayuXKbAX6BqMHpK6KrqypfEoig72oobxfhFNmctP66gUa-ILJ1Wxn1gkV58ierRThnYXs6O8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_en&type=PROGRAM&Expires=1429988311&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=IinQikLYu8~wqfB~WSgPcBas2ZzLh7qf9DRnLNdydubFBl3Y2XCRQZwIKd-KvKSXSLS6eN-5QYKNxqZRtop3-NC3iNpEAbNpnMVBaYQkYoCqbPvWB2JWX6xV-9it3bK-XPnWa~Tn~jg0EPWbRO8lkb8sXhrUfk9h19V7dCTGHQg_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_fr&type=PROGRAM&Expires=1440211468&Signature=YEqLwmEmlRo7DDmNI1VTWMzGEP9yVbYb29eRoYPwXX4FEqo2t6HNwldj~e8~oDGvXtFdjFrIw1uMR8f0Mq2fsHvByijwvkjE5fWPYKU7dgiKMk0yfGytWxug2eDLuS1qVcQ0kAtt73Rx5nT2fxG4IQ4gEF1y9vye6Nok9AYlOL4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://funny-photo-maker.ar.softonic.com/start-download/.../6ffaa5f96e593af67ab9d956a6e96adf

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1475099081&Signature=UoZSSYmW~TmafqPC~EBGESwU1QYELhm663Wf2GfX~H48~dmcjHkRP3rTuWGL10CpXufj8cveFPIZXxQMmy-9etCIW3UWprgfDmrc21paHo9nUobRPokGxaKTyPmENQXXIsbIgKuANiWeXbt8WRjjPWRcM46Grf1W4csWAuKR4x0_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1421872319&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=eOYTfePKLb88MFrcDJ0s1pU-S5Wl4q3lbRJO1k4PtNIsmdZThUevjsvJ8jFI3AjNYnMOrYRHB7Gy0WHnZYw0YTs0Szl3cbEQqd5z2Hn2XnF55g5yB9sOva8iXS8pZ-rViTxkUuH4fRVeqLO-ntVY-saexmy0ST2rFN5ZHquuQtA_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1477911644&Signature=FsT3GuwxLr1ZOLLFc32ftNClIR~SQHL0THQK74gSXN0kfLh33niLU~w8PiPSzPK~wd4SjlOoeQWDM053IUgzK1VJioay~E-pbqvA415xX0746QsccjgjyD66cqOesTxiOyumr1Fz8h85z3Z3FphvQb~EdbChnqtnSJMmq4cN84E_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_en&type=PROGRAM&Expires=1476637562&Signature=MFdPRW4wCpb2-1vSrou89hTKWX8S0aBMVJjpU1oWfctUAXtULVtZLx1yy2vqWGS1sYcEZMqZWAPtVKFM0AqQUKV-cbuYXLHn8SZraOURNjxghzzzlSsvV2rk6XPrhc6b63v3FeCdR2oMAY1o-Lnywyq53DoBbwch2IecfncDKXY_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_fr&type=PROGRAM&Expires=1428993961&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=SFm3dis~SwhEGRT5u7oTVQDtPbbTdb9~P6sQfLfz3juyCpsgDaN2ggFb1cx4xIerREjC6pw0U-cR2WN5~wLGGRC6DxN~-dbhCXB9S9bmWzvaTaHs8ifVhsrl7XaqC6YKP8nXvsCDjtBpJW7dfiA0bVVsrTi93zFa~-SFBkmKIoU_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1477565036&Signature=W-qZq4IDU56Ji9mnAC1kFOGnaRBNCYlcIRla3bnG82yAOezMtllTMUU-OaXM32fW~zdJTP9DNufoH3OtwIlbpoO9A1qf0AskA2Qib0-EUMbuT4xlnQ46qjrq5rCYPpoKX8NJcoTT2Hw9Ep~me0xtPARZV9YZs-p4ZufLnfUBVMk_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1432084822&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=F8ys189RLeyyAIxaGZD9ooiHdarJ~8qgJScfzZcTtDew8CkM3cGu6XwvgoHDD-bAIAss-nBNgdtoLP6nvbNruhoWtK83oXuOP~5QBzEJHCZKAq8pQ2gsfUz6D2MDMJHLqOfs3Vf6ZYGLb70tXBx7up~-EFMiuvceL3tFsFYK-vY_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_en&type=PROGRAM&Expires=1449047716&Signature=f654YkfTyk8V4mnpUi0o6WiOEBdL-kgxqHdJ6CSEJ5m2rCZzJZpJtxEjEClHiQ6X6i25W4hXfGbCp3Y5HXuL42Sc4m5D3x8eWPb18qmGp0ZFP6oln-XUzqS6ItEhsv0Mr0ZNn-3~-cMBdC~b2rluyy0RPIWWeTmUwz-EwZ3I9Nc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1462853693&Signature=dK5dg45eDZiVhyJ0qo-jTsy9N897gUaaXcOc1eW6axGJrjjLWTiY9ZfXG7odudlebZowgMcuJP-f67H9ouoJ3TtJHEGQiyWF-e1nGzdb3Qpy2FzuArQo7p4OrZ1etzISibtj91ezjNYDLPgyZR8iG~X92VhPnE4zuLdsQFc21P4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_br&type=PROGRAM&Expires=1468624112&Signature=gzzCh4zIhtiAMwHcNgBb49PxV5qRICSV~S4FKooCpHya5fqBXeyMjgcZOs87OxhOWQVpSYFUcQsN9rqUVQlU8rvdsNggznypkPMRQXsYWhh954INmi6wa-9CNCTrl4MrJ4W-z9CnoiSzKuIgJ8Fpr7Gk2ldAw2m3oIa3T0nfalo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

https://funny-photo-maker.softonic.com/download-tracker?th=8yS3 KGEYLiw7GKMHzA/.../9Qt4Tp0dDMO8WnqQAxNQYRz6HrD96aFCHzUP8uevl9ewLkey3JcIRhLrzK2gfHP4AwzUxrHX4Q fxjZDWPPZM6iMgR1UKZX6cGwgqU=

http://funny-photo-maker.ar.softonic.com/start-download/.../7a9c73b678dea1dc3ad92b44325ec2fa

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_fr&type=PROGRAM&Expires=1460339881&Signature=iMNFzhT4DP-JhKVunlhXun-CYa8mcDvgH5AUfm8pIPRXgUqBKnvCM1P-NkJIqv5sW5F5oC5rgs~STszgoe7RwO3ba3y1W6JYdrbU0jvZJvf6AHljqRg2KsZdlb2Mv6SqDM~K4er7eTOKL8~3sIn0ToNI-ohXWjPRZ3xzSFx75-Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_en&type=PROGRAM&Expires=1459744631&Signature=hYRVbXmJg~lom4SHxZDgRXDHDeM2jLhrMc76CbdDICLnzIan7-LNlC1xaL1hB2FovVvVC-ruYk0htIIambIMcSc99g1CdTBygxlEjcwtyKNlUno200sFkpkyHghSMIk-B41E~Sax6dUN3~ePUUNxepDKXnaLbQCIWTwowbruUFo_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_en&type=PROGRAM&Expires=1427663431&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=IyAvmH3zd0ny6jRe9WLlYLWljXZH1GFkbw3UeXV~aViOzae6fW~PvhZSadqcxRpiP4jC5a9rqEKREdV7GoBJTTqHZGk~xHPX1ZXo8IsbC0Q4bAFBDPa8aNGvloii5aUbE0VTDruFJVIL69seiAN7vBzssaIkAwOckUemTgwpNjI_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_it&type=PROGRAM&Expires=1477550222&Signature=AVsi520MtQeDouAq7mayjcHRzb88XJomJCQRslAP7TQqJP-RXJZKv8yh8i2oGdogNWDXs5ocWJKmAW9DXt9KzZHGZbRig0djiFIqkH-y9NMBJd6pWkybepxi20JFYMXH7~LQ0rMU0mLTteqoGNkiU3nn74ujfUvUFFxHCWuK-uA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1474695010&Signature=EXM2oGmMF5NNNbngLOBKq2YzM6mGtZTTBaaD1V2MeozfE6kReVLfLRbhTkhddjk3Pruv5JSXq1FXgqggT35lzFoR8qZtCeZwyg97BDCMGLn6qDRBQlG9wwvp6ZA0SwLhFLRRvkiyPo81NHSDcy0epMosb~Ry9bKImsNSYWFaaNg_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://telechargement2.pcastuces.com/temp6bs2/.../setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_en&type=PROGRAM&Expires=1453857104&Signature=MwQHAnTl3MiHd9BvuYJ93DpHxICKJhGlcVf5KoJ4UI30bKsjS2QKUiozenta7bwEJpduD81-SaRDUNyQB8jQUjy759YJ049PeSBEP3XNF30X6nzZ0pRh-rPtmjsPWZLvFULfDqpGfU3dZRbo07z96sa-vcFdf4PmsgWlgimWQww_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_es&type=PROGRAM&Expires=1426676820&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=CiMCBh4oQGiuNsrwbqhBh-ythphvLpGKKSD1lhDiYDDvoQ~VmRSpQQdwDrWLtIyVNNkx-UZxmHaO~MW14nyes8TK9p6oyv-TG4yDKGkNPCcG3arLcDeyXjlHlPV1QuzcPRbJwt16UVy5iZIOqm3RgQoug50RlmSdNV2aK5ivwyA_&filename=setup_funny_photo_maker.exe

http://gsf-cf.softonic.com/a4d/de3/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3342205&instance=softonic_it&type=PROGRAM&Expires=1476668757&Signature=F3kkd6jsdXXttzaEdocs6bVRWEo4m58ZZhjQ7akMYOwzv1Ka32O~DoWmE8uGhgNbkUvKS7Qt7-S9vdfAZxYJVc6W1YHyQDBu7PBLD5R0m9SZKzlQSaHTw-VlIYcbc3JjVhg5VNZBtbbuRFb8jiWII-WJGk9UEhXeim1OSz9KNh4_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=setup_funny_photo_maker.exe

Latest 30 of 127 download URLs

Remove setup_funny_photo_maker.exe - Powered by Reason Core Security