download-avast-free-antivirus.exe

Covus Freemium GmbH

The application download-avast-free-antivirus.exe by Covus Freemium GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. The installer is marketed through download protals and search ads as the free AVAST Antivirus but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Covus Freemium GmbH  (signed and verified)

MD5:
bccd278a049b62daec8ba56d4a212fc7

SHA-1:
dabc4019500b12ba3124cac7a8b7b1261c907832

SHA-256:
c5b0843a77ecfc429e156a30511f688aae14ba77594ca17a4e93c8d50fa648d1

Scanner detections:
1 / 68

Status:
Potentially unwanted

Explanation:
Includes bundled offers in the installer/download manager that include adware components such as Best-markit, and Search Protect (ClientConnect).

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/24/2024 7:30:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Covus (M)
17.3.12.17

File size:
576.6 KB (590,464 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\users\{user}\downloads\download-avast-free-antivirus.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/28/2013 5:21:57 PM

Valid to:
1/29/2015 5:21:57 PM

Subject:
CN=Covus Freemium GmbH, O=Covus Freemium GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211DBCB8A07ED407612FC406EFD259BE29

File PE Metadata
Compilation timestamp:
12/15/2014 6:37:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x21771

Entry point:
E8, 4F, 66, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 56, 8B, F1, 33, DB, 3B, F3, 75, 16, E8, 56, 14, 00, 00, 6A, 16, 5E, 89, 30, E8, FA, 13, 00, 00, 8B, C6, E9, 8F, 00, 00, 00, 57, 39, 5D, 08, 77, 13, E8, 3A, 14, 00, 00, 6A, 16, 5E, 89, 30, E8, DE, 13, 00, 00, 8B, C6, EB, 75, 33, C9, 39, 5D, 10, 88, 1E, 0F, 95, C1, 41, 39, 4D, 08, 77, 09, E8, 17, 14, 00, 00, 6A, 22, EB, DB, 8B, 4D, 0C, 83, C1, FE, 83, F9, 22, 77, C9, 8B, CE, 39, 5D, 10, 74, 0B, 33, DB, 43, C6, 06, 2D, 8D, 4E, 01, F7, D8, 8B, F9...
 
[+]

Entropy:
6.9638

Code size:
312 KB (319,488 bytes)

Remove download-avast-free-antivirus.exe - Powered by Reason Core Security