ac3filter_2_6_0b.exe

AC3Filter

Alexander Vigovsky

The application ac3filter_2_6_0b.exe, “AC3Filter Setup ” has been detected as a potentially unwanted program by 2 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. This file is typically installed with the program Toolwiz Time Freeze 2016 by ToolWiz. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars.
Publisher:
Alexander Vigovsky

Product:
AC3Filter

Description:
AC3Filter Setup

MD5:
5eba0624b0764cc80b787298544026c4

SHA-1:
832bf5093617711948105ff65094819fb6830c79

SHA-256:
99fb0d27a8ce74084c007992da0928c16a2929a259dc5ff5c8268aaa50f52687

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/12/2018 2:19:54 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
7.9190

Reason Heuristics
PUP.OpenCandy.Installer (L)
16.11.28.22

File size:
4 MB (4,184,641 bytes)

Product version:
2.6.0b

Copyright:
Copyright (c) 2002-2013 by Alexander Vigovsky

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ac3filter_2_6_0b.exe

File PE Metadata
Compilation timestamp:
12/20/2011 11:16:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:SO0hGzmf6bVe0n+hn4orL8gcC5pAn/WZGEMLmRqj:SfGznR+Z58g35C/0GEW6qj

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Entropy:
7.9901

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file ac3filter_2_6_0b.exe has been discovered within the following program.

www.Toolwiz.com
About 4% of users remove it
 
Powered by Should I Remove It?

The file ac3filter_2_6_0b.exe has been seen being distributed by the following 50 URLs.

http://www.free-codecs.com/download_soft.php?d=e8430a65a943267806339224349c6f5b&s=12&r=&f=ac3_filter.htm

http://www.free-codecs.com/download_soft.php?d=bb8ac3602d149ce04ae785780106d7b9&s=12&r=&f=AC3_Filter.htm

http://www.free-codecs.com/download_soft.php?d=be6972e542f2b95ba49842bc31f499ff&s=12&r=&f=ac3_filter.htm

http://www.free-codecs.com/download_soft.php?d=7f091e2ac9bbf508e9dfae132148cfed&s=12&r=&f=AC3_Filter.htm

http://www.free-codecs.com/download_soft.php?d=4a4e99495154655f2bcb83c3fde5a859&s=12&r=&f=AC3_Filter.htm

http://www.free-codecs.com/download_soft.php?d=fd63a00958d877c8064bde70cc77af9f&s=12&r=&f=ac3_filter.htm

http://a.tinhaythe.com/v2106xm/2015/3/.../ac3filter-26b.exe

https://dw.uptodown.com/dwn/r3B5cogl1K5stYNazKOddk9LSfCkYrHybGriYwH6KmGI3GkyMOQaxOPjHmlQ1oJEsP4MclRpD2BooTXqWa6nNOem1awc9WO9Sn7o6Lrj2uRe089prZH6d7WVnjqRJLCa/kgZrU9xTDlJpUPa3bPOEzUJJQkkpEZDaMtmGOEtIFuhmlMuXuT_IhRNWBduEEyEkJ_KTOa8TKJhyKcZmufef_cCvvHKxZNtdo0gHJEUiBeVDOBCHA7gGPtJvC9F1uMcP/llUyqYiUbAL8m-x97D2ftk-mwPty0YRKIYmereT-2hdXS1g3U512S7NArbIXK0R6bdLGkvbjrzBN3LPdR-Eo5-6lVFsw-_B6knYSP3dTsjFEAzepXQrTH2xVDr1xQjLI/.../

http://www.free-codecs.com/download_soft.php?d=3121a343e9cd28030bf0bfb8febef473&s=12&r=&f=ac3_filter.htm

http://www.free-codecs.com/download_soft.php?d=0cab43b7973286ee45604a35101d8d7f&s=12&r=&f=AC3_Filter.htm

http://lb.cdn.m6web.fr/d/c/a/63a0911e75f53c77cda3e1a05666d787/5842d121/soft/.../ac3filter-full_2-6-0b_fr_11064.exe

http://61.222.3.60/47d9fa79dd16cadf81f149bf130f4590/softking/soft/en/.../ac3filter_2_6_0b.exe

https://dw.uptodown.com/dwn/PyyobYhE7oif22e92upj4mLduUxHp1eq6LJpKws9M4IeMukV5tKDiWGz9A_COr7LijOlUeDyZ5RijqI0SoAfpjhHlSndws6OSU_6RvkzMt5Nzk_BMjS62kZxAqq7A2DA/gcpuFbY2_5aD6JCY05SsRKT9fcYSgz9k9Ayaa8sylPtoE1-lYua-lGGg9qDYagwIEyYbaDmgbHuKp-HoVtrv5JmnG4a7ul5p2na7-Sdq4D5Slh5KAm4RNcr_cGA5JBvV/.../

http://www.free-codecs.com/download_soft.php?d=c32e6b4bd1134d6bdf12a3f223e348ec&s=12&r=&f=ac3_filter.htm

http://dw.uptodown.com/dwn/aWHtJmgwyNI-wu_IOdf-ffgVL6e0T8Va4YBslXltag7JL9DfMevqLEqv5QcZtqsrtceZg7o6sf_RYRjtz0-NZcwIOLyitVOTB0MPlfM1_BSuYlID5eCTFDakO6gMaisQ/mp_RFGzkJmtyGI0Qbv4Siz4qnV9Lovou_xspUP4sl-0FIm200qKP34OGhTUBgLBS1miOrgXu1VKLxd3eFFSFK5JyIqtOWjJxobEW8v9xiXuva-mcUBlthlwDYm7dDKcf/0bbvhVMvSXz_V_A-Rx-nhuVPGGWZbuyNKDgn7lEONeMEhLLwoIaYMAV3hvKfCHJCCyfcM1Xe467xDUgBH9JfkQiIQFKKUcXuDYIUYMJmMAKO1i5aMfZ3FZMmy4ygjwJO/.../

http://www.free-codecs.com/download_soft.php?d=1c9fd303591693cecaee887d00f9b96f&s=12&r=&f=AC3_Filter.htm

http://www.free-codecs.com/download_soft.php?d=198d9f780ff27b5748f139de72f234a7&s=12&r=&f=ac3_filter.htm

http://61.222.3.60/fcd593f90a0e7cab8f4c043d4f485bf1/softking/soft/en/.../ac3filter_2_6_0b.exe

https://dw.uptodown.com/dwn/683B8f7TXFYLCNOtc_Vnd8mONVzQv6EBqj-_P93y1WFE6SaS-YRJmrYZTwmXKqMJeiKLyAp0K1yVxISsKDLuqmWCc_TUS6LxZUgG8KG4oPtXfh1clWf02v7VYdm6f_ZC/xh3Dvlf2Xo87DEh9CD6w2X8CXAdm978S96aw3Zd-09-PgA9BoQtHz40MbD-09xW-xm5eTWhJPY2eT_-uNktMWAGHq6sPtO8pX_2gyB1lhWfwnWzd6q84CfvrnngT2-BR/ZcaHG1ykyJ18XSa_1CoXU34Dfg71cuvzaOxToPITMCoXmL3M1PGPtR5WX97AQVRdzW_QgRI7i7-njz2oOQdSvWIy6zgMf_PrJNN7Rv2G74SivngXRBVu-sFOvv9sNS2G/.../

http://lb.cdn.m6web.fr/d/c/a/e9dfb10bf72b83547126d1317e48a47d/5869025c/soft/.../ac3filter-full_2-6-0b_fr_11064.exe

http://files4.dddload.net/download3/ac3filter/.../ac3filter_2_6_0b.exe

http://www.free-codecs.com/download_soft.php?d=03df43d612b554cca489e665d06b0716&s=12&r=&f=ac3_filter.htm

https://dw.uptodown.com/dwn/Acek-bKpXge0OMQDDe6fvZaLqdMwK9Cx7z7ytUEnnrvGMa2_r_gkzeWZQxVDgxbQv-ttNTSR_GT4yMJPk6NLnZom870PKx0a0e8LmFtII4nu7jTaXFgL8TAVCxuYdtla/8sfUbOgci8qLvSCQe3AGWJt3KYpsGiv0ULCBJ_qoZVwvdnOe0aQtzdCrOae6IE49e1ya4Sbobc4kH8BJ4v17jbDQtlNM66hPiusx0zgu3UkDz0lGakITvs6YzVVsnLXx/095Y-qOG-Nrbao0UvrfpleGY9KJqi70gjAdMnTQjhc2l0mCKSc4agKj7sicVu_ZA0-MXJO1ky8hUhOCYfWDLY_Mi-xMK6eYKDIITdzn-pDJT1-HSTtJdg4no2hT7nc0C/.../

http://www.free-codecs.com/download_soft.php?d=fc5d3ed1d15144f4aff4b1849ce82ec5&s=12&r=&f=AC3_Filter.htm

http://lb.cdn.m6web.fr/d/c/a/d318cc442dcb4f3fc14a3d93ca7c83a2/564a4c2d/soft/.../ac3filter-full_2-6-0b_fr_11064.exe

https://dw.uptodown.com/dwn/TMJYHJbu14hEgHOlCprao9Vzn4Xcjmp8K04qThPbmdGe68D_m6OdKYW6d7ytAzGLuQDY3GN3K4ow237xr31u4jmU4V_wy8B8kYD2WIMX0pjaIHBGeIGdjsG-tvz9b2Hu/CDsqICrth4y9BAcr9byEr5Bycxu8JoZMHLkZ9vpdDewbrkB8gYuAp-G9b1vBSN1pz3TGT-BfCkoDgCXBSzH2EUsDTI4_E6wu1VxmPx8CGyMF9XTS18U4TLEVWU6TeYNE/.../

http://www.free-codecs.com/download_soft.php?d=d4ba955591aa9833a34d98228fa8e4cc&s=12&r=&f=ac3_filter.htm

http://www.free-codecs.com/download_soft.php?d=c9e5a84688ac7ab5c9c532e413f62a44&s=12&r=&f=ac3_filter.htm

http://lb.cdn.m6web.fr/d/c/a/af08529f4808baad49d252964fe7048b/57fb70cf/soft/.../ac3filter-full_2-6-0b_fr_11064.exe

http://www.free-codecs.com/download_soft.php?d=c234c86b6a6437a8c5ca322cf2fc7863&s=12&r=&f=AC3_Filter.htm

Latest 30 of 145 download URLs

Remove ac3filter_2_6_0b.exe - Powered by Reason Core Security