videoconvertersetup.exe

The application videoconvertersetup.exe has been detected as a potentially unwanted program by 19 anti-malware scanners. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.videoconvertertool.net.
MD5:
5c7792a16b344f5d8aeaa671d7174d9a

SHA-1:
bb7958207960e29dae4be4d515bae7c284394dab

SHA-256:
cb61ab061256f90615c12125dd8ab7da1fa78ffab188251f5a0ba418849d2a21

Scanner detections:
19 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
4/23/2024 1:56:00 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.459595
967

Avira AntiVirus
APPL/Downloader.Gen6
7.11.121.84

Bitdefender
Adware.Generic.459595
1.0.20.815

Bkav FE
W32.Clod875.Trojan
1.3.0.4613

Comodo Security
Application.Win32.ClickRun.A
17482

Dr.Web
Adware.InstallCore.64
9.0.1.0163

Emsisoft Anti-Malware
Adware.Generic.459595
8.14.06.12.04

ESET NOD32
Win32/InstallCore.AT (variant)
8.9190

F-Secure
Adware.Generic.459595
11.2014-12-06_5

G Data
Adware.Generic.459595
14.6.22

K7 AntiVirus
Unwanted-Program
13.174.10588

McAfee
Artemis!5C7792A16B34
5600.7101

MicroWorld eScan
Adware.Generic.459595
15.0.0.489

NANO AntiVirus
Trojan.Win32.InstallCore.cqrhwb
0.28.0.57029

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.14610

Trend Micro House Call
TROJ_GEN.R0CBH0AJA13
7.2.163

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.24.3

VIPRE Antivirus
Click run software
24628

File size:
1.1 MB (1,195,416 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\videoconvertersetup.exe

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:2HE1QUJVnQDzkZHyg+6bDibpvdUnh9rS0sDN8BliRbR3Jpfx5dIOzlJ:2HuVnQDzkZHP9bDibpvdwhHFAR3JpLdr

Entry address:
0xCEC70

Entry point:
55, 8B, EC, 83, C4, F0, B8, 28, 4A, 41, 00, E8, 86, DC, FF, FF, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.9733

Developed / compiled with:
Microsoft Visual C++

Code size:
847.5 KB (867,840 bytes)

The file videoconvertersetup.exe has been seen being distributed by the following URL.

Remove videoconvertersetup.exe - Powered by Reason Core Security