hdvid-codec-chrome.exe

Rungnapa Fongkerd

The application hdvid-codec-chrome.exe by Rungnapa Fongkerd has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The setup installer will bundle multiple adware offers during download and setup (based on the user's geographical location) including toolbars, extensions and coupon utilities. The file has been seen being downloaded from www.hdvidcodecs.com.
Publisher:
Rungnapa Fongkerd  (signed and verified)

MD5:
e877459e59a0265ccd7abc854947f69d

SHA-1:
59b75674aaef50e83c61888f1273ddb29ae57e5f

SHA-256:
0c2084d42d19d6f4dffc91e2e80814b65e1aa1d0a3476fd96c034483c58c6cde

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles a number of adware programs in the installer.

Analysis date:
4/26/2024 7:34:33 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/CoolMirage.Gen
7.11.167.110

AVG
Rungnapa
2015.0.3306

Dr.Web
Adware.Downware.6586
9.0.1.0226

G Data
NSIS.Adware.OneClickDownloader
14.8.24

herdProtect (fuzzy)
2014.10.30.15

IKARUS anti.virus
AdWare.OneClickDownloader
t3scan.1.7.5.0

Malwarebytes
PUP.Optional.OneClickDownloader.A
v2014.08.14.03

Qihoo 360 Security
HEUR/Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.RungnapaFongkerd.S
14.8.14.15

Sophos
FT Downloader
4.98

Trend Micro House Call
Suspicious_GEN.F47V0807
7.2.226

VIPRE Antivirus
Trojan.Win32.Generic
32222

File size:
401.3 KB (410,960 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\hdvid-codec-chrome.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/28/2014 2:00:00 AM

Valid to:
7/29/2015 1:59:59 AM

Subject:
CN=Rungnapa Fongkerd, OU=Individual Developer, O=No Organization Affiliation, L=Phuket, S=Thailand, C=TH

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5EC13B211C7584BB92BAC58CF7ED1F63

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:jW9uwgJEzpB9HugJh3Zvfmat3JbbmFup2c:qV04Bxxb3RmaTcup2c

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file hdvid-codec-chrome.exe has been seen being distributed by the following URL.

Remove hdvid-codec-chrome.exe - Powered by Reason Core Security