videoconvertersetup.exe

The application videoconvertersetup.exe has been detected as a potentially unwanted program by 25 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from spath2.path-tracker.com.
MD5:
e8b9c835b675dbbfa43cff2faae23dcc

SHA-1:
72bb2b2a53efb97b93cb55b34da08e24b3a34a6e

SHA-256:
cb378585efae874dbf551d2d98204e9357f987845d306930dd9d8af49803b356

Scanner detections:
25 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/18/2024 4:11:17 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.463306
679

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
APPL/Downloader.Gen6
7.11.166.108

AVG
Adware InstallCore.I
2014.0.4311

Bitdefender
Adware.Generic.463306
1.0.20.430

Bkav FE
HW32.Laneul
1.3.0.4959

Clam AntiVirus
Win.Adware.463306
0.98/21411

Dr.Web
Adware.Downware.694
9.0.1.05190

Emsisoft Anti-Malware
Adware.Generic.463306
9.0.0.4799

ESET NOD32
Win32/InstallCore.AY potentially unwanted application
9.7.0.302.0

F-Prot
W32/InstallCore.P.gen
v6.4.6.5.141

F-Secure
Adware.Generic.463306
11.2015-27-03_6

G Data
Adware.Generic.463306
15.3.24

herdProtect (fuzzy)
2015.7.2.16

K7 AntiVirus
Unwanted-Program
13.183.13619

McAfee
Trojan.Artemis!415E759E439C
5600.6813

MicroWorld eScan
Adware.Generic.463306
16.0.0.258

NANO AntiVirus
Trojan.Win32.Downware.cjeaia
0.28.2.61349

Norman
Adware.Generic.463306
03.12.2014 13:20:04

Panda Antivirus
PUP/MultiToolbar.A
15.03.27.11

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Trend Micro House Call
HV_SOFTWARE_BL132891.TOMC
7.2.86

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.26.3

VIPRE Antivirus
Threat.4754767
31208

File size:
1.1 MB (1,164,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\videoconvertersetup.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Y1yrbjTWrIKRcExC2LkMSYG7LhQ/v1vUQoEk5W:YEbjTqIKRcExVLwQX5Xk5

Entry address:
0xCD430

Entry point:
55, 8B, EC, 83, C4, F0, B8, 88, 1A, 40, 00, E8, 56, CC, FF, FF, 8B, C0, FF, 25, BC, F1, 46, 00, 8B, C0, FF, 25, B8, F1, 46, 00, 8B, C0, FF, 25, B4, F1, 46, 00, 8B, C0, FF, 25, B0, F1, 46, 00, 8B, C0, FF, 25, AC, F1, 46, 00, 8B, C0, FF, 25, A8, F1, 46, 00, 8B, C0, FF, 25, A4, F1, 46, 00, 8B, C0, FF, 25, A0, F1, 46, 00, 8B, C0, FF, 25, E0, F1, 46, 00, 8B, C0, FF, 25, 9C, F1, 46, 00, 8B, C0, FF, 25, DC, F1, 46, 00, 8B, C0, FF, 25, 98, F1, 46, 00, 8B, C0, FF, 25, 94, F1, 46, 00, 8B, C0, FF, 25, 90, F1, 46, 00...
 
[+]

Entropy:
6.9917

Developed / compiled with:
Microsoft Visual C++

Code size:
837.5 KB (857,600 bytes)

The file videoconvertersetup.exe has been seen being distributed by the following URL.

Remove videoconvertersetup.exe - Powered by Reason Core Security