setupdvddecrypter_3.5.4.0.exe

The executable setupdvddecrypter_3.5.4.0.exe has been detected as malware by 9 anti-virus scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from www.dvddecrypter.org.uk.
MD5:
6c621072020eb1cb821dce9fb7615a01

SHA-1:
e49a88bacd3ad236fc1f99d1f32ea4883efe32b0

SHA-256:
bcf430f3043c84d479f90148abf12553ee015d34b1dd07afbf7c880989175a8d

Scanner detections:
9 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/26/2024 6:48:11 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160215-2

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
11.5.0.6191

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

F-Secure
Win32.Sality.3
5.15.21

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Virus.W32/Sality.gen.z
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.215.793.0

File size:
958.3 KB (981,334 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\My documents\downloads\setupdvddecrypter_3.5.4.0.exe

File PE Metadata
Compilation timestamp:
3/19/2005 3:58:24 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:dCrFlrNS+unhekfh8y44XlQds62HTreG+M/R6zEM:dCrg6b4Xlos62GvaYzD

Entry address:
0x3E6D

Entry point:
2C, 02, 0F, AF, C1, 0A, CC, 55, 68, 8C, 7A, B4, 00, 0F, AF, E9, F2, 73, 06, 69, FE, 1D, 2F, 44, F6, 72, 02, 89, C0, 8B, C7, 57, 52, 80, F6, 81, 0F, AF, C2, 0A, FE, E8, 5D, 00, 00, 00, 86, D0, FE, CE, 0F, BE, C3, 85, F3, 8D, 05, 56, 89, DB, 0C, BD, 81, D8, A9, 67, 8A, FA, EB, 04, 4D, 89, EB, F2, 72, 05, 0F, B6, CA, 87, E9, 8B, C1, 85, CF, 22, DE, 84, C8, 8D, 2D, 12, 09, 10, D0, 50, 8B, C8, 39, E9, BB, C7, A3, F9, E7, 5E, FF, CB, 0F, B7, E8, 0F, B7, ED, 05, 66, 63, AE, ED, 0F, AF, C7, 8D, 16, C6, C5, 1C, 87...
 
[+]

Code size:
22.5 KB (23,040 bytes)

The file setupdvddecrypter_3.5.4.0.exe has been seen being distributed by the following URL.

Remove setupdvddecrypter_3.5.4.0.exe - Powered by Reason Core Security