convertad.exe

The application convertad.exe has been detected as a potentially unwanted program by 18 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ConvertAd’.
Version:
1.0.0.1

MD5:
e3c832e32358bea9fc607552f2237be8

SHA-1:
526eb0657b731eead0862074f880b858bf80d1b5

SHA-256:
bf3b397f1ba63a01e2063be9155610b11880ac54ceec8ea936d4bb707eafbb98

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 7:33:54 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.957276
779

Agnitum Outpost
PUA.ConvertAd
7.1.1

avast!
Win32:Adware-CBV [PUP]
2014.9-141218

AVG
Generic6
2015.0.3257

Baidu Antivirus
Adware.Win32.ConvertAd
4.0.3.141218

Bitdefender
Application.Generic.957276
1.0.20.1760

ESET NOD32
Win32/Adware.ConvertAd (variant)
8.10852

Fortinet FortiGate
Riskware/ConvertAd
12/18/2014

F-Secure
Application.Generic.957276
11.2014-18-12_5

G Data
Application.Generic.957276
14.12.24

IKARUS anti.virus
PUA.ConvertAd
t3scan.1.8.5.0

K7 AntiVirus
Adware
13.188.14368

McAfee
Artemis!E3C832E32358
5600.6913

MicroWorld eScan
Application.Generic.957276
15.0.0.1056

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.19.0

Sophos
Generic PUA FA
4.98

Trend Micro House Call
Suspicious_GEN.F47V1203
7.2.352

VIPRE Antivirus
Trojan.Win32.Generic
35588

File size:
2 MB (2,140,672 bytes)

Product version:
1.0.0.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\convertad\convertad.exe

File PE Metadata
Compilation timestamp:
11/13/2014 10:20:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:fFFYgixz5jr8z+JK4MUxMbCqNYCl5QCSJ6nmLHl2v1mxXWTk8lA5BBmpE:NFYf5jr8KJaUACqNYCl5QCSJ6pv1mET7

Entry address:
0x148CAE

Entry point:
E8, C6, B4, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, E0, 90, 5D, 00, 75, 02, F3, C3, E9, 4D, B5, 00, 00, 8B, 41, 04, 85, C0, 75, 05, B8, B8, EC, 5A, 00, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 57, 8B, F9, 74, 2D, 56, FF, 75, 08, E8, 05, 03, 00, 00, 8D, 70, 01, 56, E8, 1A, 18, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 11, FF, 75, 08, 56, 50, E8, 13, B6, 00, 00, 83, C4, 0C, C6, 47, 08, 01, 5E, 5F, 5D, C2, 04, 00, 8B, FF, 56, 8B, F1, 80, 7E, 08, 00, 74, 09, FF, 76, 04, E8, AD, 17, 00, 00, 59, 83, 66, 04, 00, C6, 46...
 
[+]

Entropy:
6.4689

Code size:
1.5 MB (1,570,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConvertAd

Command:
C:\users\{user}\appdata\local\convertad\convertad.exe


Remove convertad.exe - Powered by Reason Core Security