divxupdate.exe

The application divxupdate.exe has been detected as a potentially unwanted program by 26 anti-malware scanners. This is a setup program which is used to install the application. The file has been seen being downloaded from selectedloads.com.
MD5:
9f069ad7899862b116e14e706e4472f3

SHA-1:
488cc9e6a5fdc8e2890f15490523407b1d39b8aa

SHA-256:
5dc672368142447da3fbe4700e6804e12ee2aa447f177322971c1af275d45b9a

Scanner detections:
26 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 4:48:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Adware.WSM
360

Agnitum Outpost
PUA.ToolPlugin
7.1.1

Avira AntiVirus
Adware/Agent.wxf.4
7.11.144.106

avast!
Win32:Dropper-gen [Drp]
2014.9-160209

AVG
Generic4
2017.0.2838

Baidu Antivirus
Adware.Win32.Agent
4.0.3.1629

Bitdefender
Win32.Adware.WSM
1.0.20.200

Bkav FE
W32.Clod41a.Trojan
1.3.0.4959

Comodo Security
UnclassifiedMalware
18132

Dr.Web
Trojan.Click2.59772
9.0.1.040

Emsisoft Anti-Malware
Win32.Adware.WSM
8.16.02.09.05

ESET NOD32
Win32/Adware.ToolPlugin
10.9699

Fortinet FortiGate
W32/Adware_fam.NB
2/9/2016

F-Secure
Win32.Adware.WSM
11.2016-09-02_3

G Data
Win32.Adware.WSM
16.2.24

K7 AntiVirus
Adware
13.176.11806

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.686

McAfee
Artemis!9F069AD78998
5600.6494

MicroWorld eScan
Win32.Adware.WSM
17.0.0.120

NANO AntiVirus
Trojan.Win32.ToolPlugin.uwvez
0.28.0.59288

nProtect
Win32.Adware.WSM
14.04.18.01

Sophos
Troj/Dloadr-DKG
4.98

Trend Micro House Call
TROJ_GEN.RCBOCJQ
7.2.40

Trend Micro
TROJ_GEN.RCBOCJQ
10.465.09

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
28400

File size:
1.2 MB (1,249,280 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\divxupdate.exe

File PE Metadata
Compilation timestamp:
11/2/2009 9:24:15 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:sZc3qxH5721suv7wQFgbiJGNRXuI2NW7qtm8XxWOOErUoe1f:d6Z572jWiJGjO4GhROErUoep

Entry address:
0xAF1E

Entry point:
E8, 6E, 4A, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, D0, 4B, 42, 00, 89, 0D, CC, 4B, 42, 00, 89, 15, C8, 4B, 42, 00, 89, 1D, C4, 4B, 42, 00, 89, 35, C0, 4B, 42, 00, 89, 3D, BC, 4B, 42, 00, 66, 8C, 15, E8, 4B, 42, 00, 66, 8C, 0D, DC, 4B, 42, 00, 66, 8C, 1D, B8, 4B, 42, 00, 66, 8C, 05, B4, 4B, 42, 00, 66, 8C, 25, B0, 4B, 42, 00, 66, 8C, 2D, AC, 4B, 42, 00, 9C, 8F, 05, E0, 4B, 42, 00, 8B, 45, 00, A3, D4, 4B, 42, 00, 8B, 45, 04, A3, D8, 4B, 42, 00, 8D, 45, 08, A3, E4, 4B, 42, 00, 8B...
 
[+]

Code size:
76 KB (77,824 bytes)

The file divxupdate.exe has been seen being distributed by the following URL.

Remove divxupdate.exe - Powered by Reason Core Security