zczcgvwh.exe

Freemium GmbH

The file zczcgvwh.exe by Freemium GmbH has been detected as a potentially unwanted program by 14 anti-malware scanners. The program is a setup application that uses the Covus installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. It is also typically executed from the user's temporary directory.
Publisher:
Freemium GmbH  (signed and verified)

MD5:
ae6d4f75c8d81f32ab66f2b3101a1737

SHA-1:
eb378dc77215ea115a82f16ec3653bf4b6dd32c5

SHA-256:
215ea8ba3d906a3d7515d0896072d665939f67df89e79b9cd8426d6f37c99714

Scanner detections:
14 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:15:45 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
PUA/DownloadGuide.Gen
3.6.1.96

AVG
Generic
2016.0.3151

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.1577

Dr.Web
Adware.Downware.10484
9.0.1.092

ESET NOD32
Win32/DownloadGuide.F potentially unwanted
9.11424

herdProtect (fuzzy)
2015.7.7.16

K7 AntiVirus
Unwanted-Program
13.202.15469

Kaspersky
not-a-virus:Downloader.Win32.DownloadHelper
15.0.0.543

McAfee
Artemis!AB91B06573ED
5600.6711

NANO AntiVirus
Riskware.Nsis.Adware.dpxxla
0.30.8.659

Reason Heuristics
PUP.Bundler.Covus
15.4.2.22

Sophos
Generic PUA DO
4.98

Trend Micro House Call
Suspicious_GEN.F47V0321
7.2.188

VIPRE Antivirus
Threat.4150696
38950

File size:
365.2 KB (373,936 bytes)

Bundler/Installer:
Covus (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\local\temp\zczcgvwh.exe.part

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
12/29/2014 4:41:38 PM

Valid to:
12/29/2015 4:41:38 PM

Subject:
CN=Freemium GmbH, O=Freemium GmbH, L=Berlin, C=DE

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00FEAC9D237F1C5C86

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:yQqX0l8pyl3IH7SqHKw/9VfoYq9dK+eh/yivTegyKM3D6cq0QFF8kvlQ3:u0lgBz99N9+myimKM3DLMmUQ3

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 3F, 42, 00, E8, F1, 2B, 00, 00, A3, 84, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 36, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Remove zczcgvwh.exe - Powered by Reason Core Security