freevideoconvertersetup-r0-n-bc.exe

Free Video Converter

Koyote-Lab Inc.

The application freevideoconvertersetup-r0-n-bc.exe, “Free Video Converter Install” by Koyote-Lab has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from www.koyotesoft.com.
Publisher:
Koyote-Lab Inc  (signed by Koyote-Lab Inc.)

Product:
Free Video Converter

Description:
Free Video Converter Install

Version:
1.0.0.135585

MD5:
23df4cb713fb02754acb83aae167aeb8

SHA-1:
13ee43c3a9fee9a9ef0917de5d879448591033bc

SHA-256:
7be95d15bd9f9b6d8544e10a34f69c3951460e01b95ddbc1ea9855efcac74413

Scanner detections:
14 / 68

Status:
Potentially unwanted

Analysis date:
4/27/2024 12:51:02 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/SearchSuite
2015.02.17

Avira AntiVirus
Adware/SeaSuite.ona
7.11.210.142

AVG
SearchSuite
2016.0.3196

Dr.Web
Adware.Bandoo.167
9.0.1.047

ESET NOD32
Win32/Toolbar.SearchSuite potentially unwanted
9.11186

G Data
Win32.Application.KoyoteLab
15.2.25

IKARUS anti.virus
PUA.Soffer
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.195.14983

Malwarebytes
PUP.Optional.Koyote.A
v2015.02.16.11

McAfee
Artemis!23DF4CB713FB
5600.6852

NANO AntiVirus
Riskware.Win32.Bandoo.dgnlaz
0.30.0.65070

Reason Heuristics
PUP.Installer.KoyoteLab
15.2.16.23

Sophos
SearchSuite
4.98

Trend Micro House Call
Suspicious_GEN.F47V0211
7.2.47

File size:
1.3 MB (1,317,112 bytes)

Product version:
1.0.0.135585

Copyright:
Copyright (c) 2015

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\opera\freevideoconvertersetup-r0-n-bc.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/11/2014 9:00:00 PM

Valid to:
2/21/2016 8:59:59 PM

Subject:
CN=Koyote-Lab Inc., OU=DEV, O=Koyote-Lab Inc., L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
05787E08EB7454E434F666A81F251A2D

File PE Metadata
Compilation timestamp:
2/24/2012 4:20:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:opgzU1HgqUM/MPRocgqcytE4nllCihgSF53TxOlQPdwhNl:5g5gY5Kiihg2TKQ1i

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, C0, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 36, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 84, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 18, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 06, 27, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
29 KB (29,696 bytes)

The file freevideoconvertersetup-r0-n-bc.exe has been seen being distributed by the following URL.

Remove freevideoconvertersetup-r0-n-bc.exe - Powered by Reason Core Security