siw13-setup.exe

SIW

Topala Software Solutions

The application siw13-setup.exe by Topala Software Solutions has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup and installation application and has been known to bundle potentially unwanted software. This file is typically installed with the program SIW 2013 Home Edition by Topala Software Solutions. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Topala Software Solutions   (signed by Topala Software Solutions)

Product:
SIW

Version:
2013.05.14

MD5:
cec21500d7bfebc1dd5bb371a9816829

SHA-1:
5370f1df889f220a7ee55c6bc9031df0ac3eaf99

SHA-256:
28fd615a8233622a34965b495f810607b27ec99c4f739f184d8569d635da70cb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/7/2025 10:39:23 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.TopalaSoftwareSolutions.Installer (M)
15.7.26.12

File size:
4.3 MB (4,524,952 bytes)

Product version:
2013.05.14

Copyright:
Copyright © 2005 - 2013 Topala Software Solutions

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/4/2012 2:00:00 AM

Valid to:
5/5/2015 1:59:59 AM

Subject:
CN=Topala Software Solutions, O=Topala Software Solutions, STREET="22 Elkhorn Dr., #251", PostalCode=M2K 1J4, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F1E362709E9545879CCFC63C3E7D085D

File PE Metadata
Compilation timestamp:
1/30/2013 3:21:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:PAkWjArPZS7E+m9bhFev7D56hUorcM7Bz+V42q92kis4B1qjLNT72WpxbIlsXCTU:oTqP97eDgvBzZaSu6Lt2WpBa5T8M6sB

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file siw13-setup.exe has been discovered within the following program.

SIW 2013 Home Edition  by Topala Software Solutions
www.gtopala.com
About 4% of users remove it
 
Powered by Should I Remove It?

The file siw13-setup.exe has been seen being distributed by the following 5 URLs.

http://gsf-cf.softonic.com/537/0f1/.../file?SD_used=0&channel=WEB&fdh=no&id_file=117092&instance=softonic_br&type=PROGRAM&Expires=1487137547&Signature=NY19QyUw0CVe7NA6~uASonp3U9K86RI1RtpZ5oLOq1jCrJEmnmD0oCTycPvi7wDvyF0~F~szc33d~ZR0l1hlSo207AJco~np4DYDh09fot~89ZemdB1ntE2QoP1SFj0dqTCDHDszB4YouWaemD3FEOeVS662oecGQobiNPvHB6c_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=siw13-setup.exe

Remove siw13-setup.exe - Powered by Reason Core Security