webcamsurveyor-setup.exe

Webcam Surveyor

Aleksey Remizov

The application webcamsurveyor-setup.exe, “Webcam Surveyor Setup ” by Aleksey Remizov has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Inno Setup installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from soft.mydiv.net and multiple other hosts.
Publisher:
El Software Solutions   (signed by Aleksey Remizov)

Product:
Webcam Surveyor

Description:
Webcam Surveyor Setup

Version:
3.5.0.1028

MD5:
3b35d87834b263316af0740bbbdeb135

SHA-1:
1cec81f180b27bb46b69df4a9ba13f714cb40b4b

SHA-256:
a8017ba944b3190c7206ec67560828947aa3ffaada0ad04aefebd8f20ab1cf22

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
11/24/2024 8:03:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallCore.CSH (L)
16.12.11.3

File size:
3.1 MB (3,279,880 bytes)

Product version:
3.5.0.1028

Copyright:
Copyright © 2005-2016 El Software Solutions

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\webcamsurveyor-setup.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
2/12/2016 10:18:03 PM

Valid to:
2/12/2018 10:18:03 PM

Subject:
CN=Aleksey Remizov, O=Aleksey Remizov, L=Voronezh, S=Voronezh Oblast, C=RU

Issuer:
CN=StartCom Class 2 Object CA, OU=StartCom Certification Authority, O=StartCom Ltd., C=IL

Serial number:
4B487570DDCD7E155F3FDC689AD4B0FF

File PE Metadata
Compilation timestamp:
6/20/1992 5:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xA5F8

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, CE, 8A, FF, FF, E8, D5, 9C, FF, FF, E8, 64, 9F, FF, FF, E8, 07, A0, FF, FF, E8, A6, BF, FF, FF, E8, 11, E9, FF, FF, E8, 78, EA, FF, FF, 33, C0, 55, 68, C9, AC, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 92, AC, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 26, F5, FF, FF, E8, 11, F1, FF, FF, 80, 3D, 34, B2, 40, 00, 00, 74, 0C, E8, 23, F6, FF, FF, 33, C0, E8, C4, 97, FF, FF, 8D, 55, F0, 33, C0, E8, B6, C5, FF, FF, 8B, 55...
 
[+]

Entropy:
7.9974

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
39.5 KB (40,448 bytes)

The file webcamsurveyor-setup.exe has been seen being distributed by the following 3 URLs.

http://soft.mydiv.net/win/dlfile93100_321788/.../WebcamSurveyor-setup.exe

http://www.webcamsurveyor.com/WebcamSurveyor-setup.exe

http://mirror2.el-software.com/WebcamSurveyor-setup.exe

Remove webcamsurveyor-setup.exe - Powered by Reason Core Security