acdsee.exe

ACD_WebInstaller(FR)

The executable acdsee.exe has been detected as malware by 8 anti-virus scanners. The program is a setup application that uses the Nullsoft Scriptable Install System installer, however the file is not signed with an authenticode signature from a trusted source. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from dl.acdsystems.com.
Product:
ACD_WebInstaller(FR)

Version:
1.0.0.0

MD5:
323ca075c21aa887f0e6cdf88ca6fb99

SHA-1:
017e33d45080f5367bd073490707134fd14106db

SHA-256:
7379d25a38cb4b091a62944d4ae75172cb8763bddacf72efdd8587fff0f83769

Scanner detections:
8 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/19/2024 10:24:44 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160708-3

AVG
Win32/Sality
2015.0.4591

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
8.0.319.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

Microsoft Security Essentials
Threat.Undefined
1.225.1401.0

Norman
Win32.Sality.3
19.05.2016 01:04:49

File size:
1.3 MB (1,394,328 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (c) 2015 ACD Systems International Inc.

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Language:
English (United States)

Common path:
C:\users\{user}\downloads\acdsee.exe

File PE Metadata
Compilation timestamp:
12/6/2009 6:50:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:VFsk6XmovaHRQcZkgGu2Gz33yhETBZkNAxceZMXd4XJItZqHnphE/1TREXMSqlBK:LovaHOcrGaz2EvsJt4XGrqHnphENT/92

Entry address:
0x30CB

Entry point:
F7, DE, 85, F6, EB, 02, 8B, DE, 31, EB, BF, 65, 19, 00, 00, FF, C1, 81, F7, E7, E6, 00, 00, 81, E6, 85, 86, 3A, 3A, 81, F7, CC, 0B, 00, 00, C6, C5, 32, 51, C7, C3, D7, 2D, C9, 56, E8, 2B, 00, 00, 00, 72, 13, 0D, 8F, 7F, D3, A4, 8D, 3D, 79, BF, B2, 16, F6, C6, 19, B8, 37, 34, F4, 46, 0F, C9, EB, 03, C6, C1, 8E, 81, C5, 49, 6F, 00, 00, 80, C5, 3B, 81, ED, EF, 14, 00, 00, B6, A3, 81, FD, 5A, 74, 00, 00, 74, 03, 0F, BF, F6, BB, 13, 71, 6D, 21, 38, E7, 8D, 3A, 0F, B6, D6, 69, C6, 98, 28, 2C, C3, 03, EF, 81, F9...
 
[+]

Entropy:
7.7234  (probably packed)

Code size:
22.5 KB (23,040 bytes)

The file acdsee.exe has been seen being distributed by the following URL.

Remove acdsee.exe - Powered by Reason Core Security