mp4tovideo_install.exe

Leawo MP4 Converter

Leawo Software Co.,Ltd.

The application mp4tovideo_install.exe, “Leawo MP4 Converter 2.0 Setup ” has been detected as a potentially unwanted program by 4 anti-malware scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
Leawo Software Co.,Ltd.

Product:
Leawo MP4 Converter

Description:
Leawo MP4 Converter 2.0 Setup

Version:
5.1.0.0

MD5:
ef9f3632d13bb7ad16be8817508142b5

SHA-1:
9138b90e512321de3dc4ebbb63c600b22388bc9e

SHA-256:
235ac9eb8f6e95e847af2b50cade143b5b77ad8165fbc2b5642b1ce532403b74

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 7:45:16 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADSPY/NaviPromo.J
8.3.1.6

avast!
Win32:Relevant-X [PUP]
2014.9-150529

AVG
RelevantKnowledge
2016.0.3095

Dr.Web
Trojan.DownLoader7.55414
9.0.1.0149

File size:
27.1 MB (28,454,312 bytes)

Product version:
5.1.0.0

Copyright:
Copyright 2006-2012 Leawo Software Co.,LTD.

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\mp4tovideo_install.exe

File PE Metadata
Compilation timestamp:
6/10/2010 10:33:52 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
786432:O+kmQr9OERHgowP5++53AINQ5GZlbErnDnek8l:vkmimP5+TIN1YekW

Entry address:
0x163C4

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 54, 55, 41, 00, E8, 70, 04, FF, FF, 33, C0, 55, 68, 91, 6A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 4D, 6A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, A6, EF, FF, FF, E8, B1, EA, FF, FF, 8D, 55, EC, 33, C0, E8, FB, 87, FF, FF, 8B, 55, EC, B8, A8, D6, 41, 00, E8, A6, EA, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, A8, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
85 KB (87,040 bytes)

The file mp4tovideo_install.exe has been seen being distributed by the following URL.

Remove mp4tovideo_install.exe - Powered by Reason Core Security