vcdcuttersetup.exe

VCD Cutter

The application vcdcuttersetup.exe, “VCD Cutter Setup ” has been detected as a potentially unwanted program by 6 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. During install, it bundles potentially unwanted software on a user's computer at the same time without adequate consent. The file has been seen being downloaded from www.ranchmetabits.com and multiple other hosts.
Product:
VCD Cutter

Description:
VCD Cutter Setup

Version:
1.1

MD5:
981bc1196bd97111749f942836ce33fc

SHA-1:
964291e2920933346f13df67637f8b13ad71ab46

SHA-256:
2b02fcbf5cc0bdd979b9f49f47036de3caa448146742a95b69f007ae7159c9d6

Scanner detections:
6 / 68

Status:
Potentially unwanted

Explanation:
May bundle additional potentially unwanted software such as adware during setup.

Analysis date:
5/4/2024 6:08:38 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADSPY/NaviPromo.J
7.11.214.232

avast!
Win32:Relevant-S [PUP]
2014.9-150318

Baidu Antivirus
PUA.Win32.BundleLoader
4.0.3.15318

ESET NOD32
Win32/BundleLoader.B potentially unwanted
9.11287

Malwarebytes
PUP.Optional.BundleInstaller.A
v2015.03.18.09

Trend Micro House Call
TROJ_GEN.R02SH07BL15
7.2.77

File size:
3.3 MB (3,480,046 bytes)

Product version:
1.1

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\all\vcdcuttersetup.exe

File PE Metadata
Compilation timestamp:
1/30/2013 5:51:56 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:C1rGfzlpYQ5EO+JArhmXyHyu1YBr0u0JT0W0OssWtYSBuX/tvQmPOmH3PRctMfm9:MaRKOYArhmXyzOrwu79B2mmPdCBL

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9875

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file vcdcuttersetup.exe has been seen being distributed by the following 2 URLs.

http://www.ranchmetabits.com/ DHmiOeDVVmduVeMRzGKiR67VIpgn9YiN5CiV3F1cYcdLDDbCKB8hZO7tOtEDcIOPesbzoF0qwpHJfCSfEoDz mNZjudHipN7xc90wwuKaT1jcH5XzUrPUyjj9BtsQR0 zmFUsfQnsCW2 I7BXZjNOKSwDzu4IFmJqofOs4wOe2VwvrTiZvLxMs4sRUg7LZFsoBbV1f DZCy1OzDL_53LAvb8AIYLA==-G90CAGSwzfePByaIzhEvxVJe2BdqqASDiRywt8UQ80nsvXHgyRojP4vAnJ oezfp kDNgvc6wAA0WDU4CMf5iC9_rdvbsEfEYUObHYTVr7U6k0AxKsMEQ4zkVfYO9lRDZTTPJ968iINnaY21z_LVOKIYYcSwzElG5CDK8nV9KonTzYg7CXMKpbEA FmU9qitpikSTip5jREczPtv4shNV wgTt4Cxrc4N6flyrG AdOFq4yn4pkpXbROOJhkgoTo_BDZmN_AiUa7Gv9eEUVEGKzreBvEv5ex3RVTzIwmWwWdpLzAy18v M4U34Vb2gQMpfTq7pdDFk TGy4 UYmeqF3tGxUIUNtv QM2BjOWfqDbMYHJKskKe7Gc2V9I5MWBt4uQtPurGBzxYMoLXePhc_exfbxOhf18rN1tpM0wDSrAbAX_DIStzOyQMxqGLaa61DCDpFG98rj0nE ckuuPUzLjFqxJm Q3gwAtl_E0BAMrcFg tHVGLPmajso0N0AAUbVVl0Kn_naRJ6p1baPxubUeS7eu1pnHdBAP2 p5bR7UdUavOTl8S4EoungiBy1q04mVCm3AyebpwKD0gnyqryQZCYAK13ZqHvkthU1fhx5iqKNkR7pNp1eaA7QtccjrklE_lwOmB8w66Rn2 F_rnEUQjOQcO1LToY_WKHiS2n7 _Kzjjig6AH9axxiw0diyTSAptKeezfYwa01GL6rX8fwpbA8_1mMGKo41Sb2NDl

Remove vcdcuttersetup.exe - Powered by Reason Core Security