avc-free.exe

Any Video Converter

AnvSoft Co., Ltd.

This is a setup and installation application. The file has been seen being downloaded from www.filepuma.com and multiple other hosts.
Publisher:
Any-Video-Converter.com   (signed by AnvSoft Co., Ltd.)

Product:
Any Video Converter

Description:
Any Video Converter Setup

Version:
5.5.8

MD5:
46780bab1797d66b3c46168ba4868a2d

SHA-1:
2feb417894e6c5e60bb62ddb12511a67d41d6646

SHA-256:
c3c953c5f94a4ba3d6a37cde25e7ae7f18d8e208aec2be329222fd1f604beabc

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
12/24/2024 11:22:59 AM UTC  (today)

Scan engine
Detection
Engine version

Emsisoft Anti-Malware
JS:Trojan.Script.WF
8.14.03.26.11

ESET NOD32
8.9597

Trend Micro House Call
TROJ_GEN.F47V0228
7.2.85

File size:
30 MB (31,429,160 bytes)

Product version:
5.5.8

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\avc-free.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/14/2012 8:00:00 PM

Valid to:
8/14/2014 7:59:59 PM

Subject:
CN="AnvSoft Co., Ltd.", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="AnvSoft Co., Ltd.", L=Shenzhen, S=Guang Dong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
765E3E079F21928954D8BEC66D023B52

File PE Metadata
Compilation timestamp:
10/13/2013 4:19:32 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:YToD6/qL6C3KOHO2U+uRaEL/4WXyl9l1JXD8Nhd/nq8AOyU1k8IZwg3jhAehgRN6:YFC3KQoLjy7JX2LDuNSg3uehgRW9uBsN

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9997

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file avc-free.exe has been discovered within the following programs.

360Amigo is registry optimizer. 360Amigo System Speedup bundles a branded version of the Conduit Toolbar, designed to deliver search based advertising and results. During installation the user is presented in some cases with the option to install the toolbar (on by default).
www.360amigo.com
53% remove it
8% remove it
MyHarmony  by Logitech Inc.
3% remove it
 
Powered by Should I Remove It?

The file avc-free.exe has been seen being distributed by the following 24 URLs.

http://www.filepuma.com/file/1395214372c5423/any_video_converter_5.5.8/.../0/

http://letoltes.szoftverbazis.hu/NT5BOgMGuGjZGZMOiWm44A/1477425317/.../avc-free.exe

http://letoltes.szoftverbazis.hu/ZfHbJTfXowaWOkBOlmx1Qw/1477921556/.../avc-free.exe

http://letoltes.szoftverbazis.hu/DYx5cmDchi9PJEoAOQb8eA/1451566037/.../avc-free.exe

http://letoltes.szoftverbazis.hu/D-6VA8hYKGP6LZdmMIAc7w/1448820012/.../avc-free.exe

http://letoltes.szoftverbazis.hu/65zjoxLD01HCAIU5VjwNOA/1475345076/.../avc-free.exe

http://letoltes.szoftverbazis.hu/nqyUITzE2MVLlIrgl0_tRw/1479369206/.../avc-free.exe

http://downloads.zamunda.eu/static/files/any-video-converter/.../avc-free.exe

http://letoltes.szoftverbazis.hu/PU9xyknXQUGVw8BiHVVH0Q/1477131940/.../avc-free.exe

http://letoltes.szoftverbazis.hu/cjURwBuiqIILLq0VtKEARA/1479229374/.../avc-free.exe

http://letoltes.szoftverbazis.hu/sJBk-hqXkwzasB1LBAXrkA/1477993629/.../avc-free.exe

http://letoltes.szoftverbazis.hu/g9EUjC8AGQ46E0ExOK2vBg/1481096166/.../avc-free.exe

http://letoltes.szoftverbazis.hu/zFKosLGiFPjS0Yl1f18FCw/1440693084/.../avc-free.exe

Scan avc-free.exe - Powered by Reason Core Security