videoconvertersetup.exe

The application videoconvertersetup.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.videoconvertertool.net.
MD5:
41486fe6fc8968dc9797da5794f6307a

SHA-1:
8efe7ebdf9876f67e57eecf709b0c6be9046b59b

SHA-256:
3f6a9b8e20663b13ea425ee75004b4b0c6bb67936d48a15e300cb811e96b34b2

Scanner detections:
19 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/25/2024 11:24:04 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.InstallCore.BJ
759

Avira AntiVirus
APPL/Downloader.Gen6
7.11.122.50

avast!
Win32:InstallCore-GP [PUP]
2014.9-150106

Bitdefender
Application.InstallCore.BJ
1.0.20.30

Clam AntiVirus
Win.Trojan.Installcore-84
0.98/18355

Comodo Security
Application.Win32.ClickRun.J
17501

Dr.Web
Adware.MediaFinder.2
9.0.1.06

ESET NOD32
Win32/InstallCore.AL (variant)
9.9190

F-Prot
W32/InstallCore.V2.gen
v6.4.7.1.166

F-Secure
Application.InstallCore.BJ
11.2015-06-01_3

G Data
Application.InstallCore.BJ
15.1.22

K7 AntiVirus
Trojan
13.174.10623

McAfee
Artemis!41486FE6FC89
5600.6893

MicroWorld eScan
Application.InstallCore.BJ
16.0.0.18

NANO AntiVirus
Trojan.Win32.MediaFinder.bbmoan
0.28.0.57029

Rising Antivirus
PE:Malware.InstallCore!6.1FC
23.00.65.15104

Trend Micro House Call
TROJ_GEN.R0CBH05LJ13
7.2.6

VIPRE Antivirus
Click run software
24766

File size:
1.1 MB (1,149,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\videoconvertersetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:Lhq+mhr1TjxQI6mHX2VW2ciBvvRpEOiSRkJn75y9iMKOK:o+y1/cVWviBv/EOiSm1VrMKO

Entry address:
0xCB830

Entry point:
55, 8B, EC, 83, C4, F0, B8, 48, 4A, 40, 00, E8, 72, E5, FF, FF, 56, 57, 55, 51, 8B, F1, 89, 14, 24, 8B, E8, 8B, 5D, 00, 8B, 04, 24, 8B, 10, 89, 16, 8B, 50, 04, 89, 56, 04, 8B, 3B, 8B, 43, 08, 8B, D0, 03, 53, 0C, 3B, 16, 75, 14, 8B, C3, E8, B7, FF, FF, FF, 8B, 43, 08, 89, 06, 8B, 43, 0C, 01, 46, 04, EB, 16, 8B, 16, 03, 56, 04, 3B, C2, 75, 0D, 8B, C3, E8, 9A, FF, FF, FF, 8B, 43, 0C, 01, 46, 04, 8B, DF, 3B, EB, 75, C2, 8B, D6, 8B, C5, E8, 55, FF, FF, FF, 84, C0, 75, 04, 33, C0, 89, 06, 5A, 5D, 5F, 5E, 5B, C3...
 
[+]

Entropy:
6.9854

Developed / compiled with:
Microsoft Visual C++

Code size:
829.5 KB (849,408 bytes)

The file videoconvertersetup.exe has been seen being distributed by the following URL.

Remove videoconvertersetup.exe - Powered by Reason Core Security