convertad.exe

The application convertad.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘ConvertAd’.
Version:
1.0.0.1

MD5:
4e4897dd30cc62af7ecf28a3ef39583f

SHA-1:
55cb75345437599449744c9b5c01a524c0a6f03f

SHA-256:
4ff616d1e583078ba1ff79302a1c747dcae183bbc2f915423020a189a2d85157

Scanner detections:
19 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 1:48:42 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.952887
778

Agnitum Outpost
PUA.ConvertAd
7.1.1

avast!
Win32:Adware-gen [Adw]
2014.9-141219

AVG
Generic6
2015.0.3256

Bitdefender
Application.Generic.952887
1.0.20.1765

Clam AntiVirus
Win.Adware.977978
0.98/20220

Dr.Web
Adware.ClickMeIn.58
9.0.1.05190

ESET NOD32
Win32/Adware.ConvertAd
8.10893

Fortinet FortiGate
Riskware/ConvertAd
12/19/2014

F-Secure
Application.Generic.952887
11.2014-19-12_6

G Data
Application.Generic.952887
14.12.24

IKARUS anti.virus
PUA.ConvertAd
t3scan.1.8.5.0

K7 AntiVirus
Adware
13.188.14368

McAfee
Artemis!FA0446B79E5F
5600.6912

MicroWorld eScan
Application.Generic.952887
15.0.0.1059

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.19.0

Sophos
Generic PUA FA
4.98

Trend Micro House Call
Suspicious_GEN.F47V1207
7.2.353

VIPRE Antivirus
Trojan.Win32.Generic
35820

File size:
2 MB (2,140,672 bytes)

Product version:
1.0.0.1

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\convertad\convertad.exe

File PE Metadata
Compilation timestamp:
11/18/2014 7:18:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:UFFYgixz5jr8z+JK4MUxMbCqNYCl5QCSJ6nmLHl2v1mxXWTk8lA5BBWpE:qFYf5jr8KJaUACqNYCl5QCSJ6pv1mETj

Entry address:
0x148CAE

Entry point:
E8, C6, B4, 00, 00, E9, 89, FE, FF, FF, 3B, 0D, E0, 90, 5D, 00, 75, 02, F3, C3, E9, 4D, B5, 00, 00, 8B, 41, 04, 85, C0, 75, 05, B8, B8, EC, 5A, 00, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 57, 8B, F9, 74, 2D, 56, FF, 75, 08, E8, 05, 03, 00, 00, 8D, 70, 01, 56, E8, 1A, 18, 00, 00, 59, 59, 89, 47, 04, 85, C0, 74, 11, FF, 75, 08, 56, 50, E8, 13, B6, 00, 00, 83, C4, 0C, C6, 47, 08, 01, 5E, 5F, 5D, C2, 04, 00, 8B, FF, 56, 8B, F1, 80, 7E, 08, 00, 74, 09, FF, 76, 04, E8, AD, 17, 00, 00, 59, 83, 66, 04, 00, C6, 46...
 
[+]

Entropy:
6.4689

Code size:
1.5 MB (1,570,304 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ConvertAd

Command:
C:\users\{user}\appdata\local\convertad\convertad.exe


Remove convertad.exe - Powered by Reason Core Security