typingmaster10load.exe

Typing Master 10

Typing Innovation Group Ltd

The application typingmaster10load.exe by Typing Innovation Group has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from www.typingmaster.com and multiple other hosts.
Publisher:
Typing Innovation Group Ltd   (signed by Typing Innovation Group Ltd)

Product:
Typing Master 10

Version:
10.00

MD5:
0fc624b3276414c79e0f105296b0eb68

SHA-1:
28ac1e8425067d38d365b4b536e2668730d00976

SHA-256:
23b9ef84a7589aa73c6f6325a18a87d958c2a0ae9279775c8db0d79afee24a48

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/26/2024 7:09:24 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.OpenCandy.116
9.0.1.0108

ESET NOD32
Win32/OpenCandy.C potentially unsafe (variant)
9.11493

herdProtect (fuzzy)
2015.7.19.19

Trend Micro House Call
ADW_OPENCANDY
7.2.108

Trend Micro
ADW_OPENCANDY
10.465.18

File size:
4.4 MB (4,571,832 bytes)

Product version:
10.1.1.845

Copyright:
Copyright 2015 Typing Innovation Group Ltd.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\typingmaster10load.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/22/2014 12:00:00 AM

Valid to:
10/21/2016 11:59:59 PM

Subject:
CN=Typing Innovation Group Ltd, O=Typing Innovation Group Ltd, STREET=Eerikinkatu 4 A 16, L=Helsinki, S=Uusimaa, PostalCode=00100, C=FI

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00C56433002A6A3169BE9DD968A2B63114

File PE Metadata
Compilation timestamp:
6/19/1992 10:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:51e1IGbIF4S2l9RbbmNSy/GWlxeG0kOXqIdXX9U:oIKlDbGSy/xe5kO6IHU

Entry address:
0x9A58

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 6E, 96, FF, FF, E8, 75, A8, FF, FF, E8, A0, CA, FF, FF, E8, E7, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, 0B, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, D4, A0, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, AC, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, 1F, 97, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file typingmaster10load.exe has been seen being distributed by the following 7 URLs.

http://www.typingmaster.com/gettmpro.asp

Remove typingmaster10load.exe - Powered by Reason Core Security