codec.exe

App Loader

The application codec.exe has been detected as a potentially unwanted program by 4 anti-malware scanners. This is a setup program which is used to install the application. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The file has been seen being downloaded from down.pe-waxo.com.
Product:
App Loader

Version:
1.0.0.0

MD5:
ad6dbb66f9d2a518a55a86789250dc2d

SHA-1:
f2bcc2e3d01d2956cf56129a338f23393811c7d4

SHA-256:
48dbdfd8cedc68b3e91cb4beb10ed31ad70b82b8fc9e542b6a59982546228ef1

Scanner detections:
4 / 68

Status:
Potentially unwanted

Analysis date:
11/30/2024 10:24:25 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-gen [Adw]
160518-2

AVG
Adware Generic6.AJDA
2015.0.4568

ESET NOD32
Win32/Adware.PEerMarket.A application
8.0.319.0

Norman
Application.Bundler.LX
22.05.2016 07:18:28

File size:
250.8 KB (256,770 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\codec.exe

File PE Metadata
Compilation timestamp:
4/7/2015 2:12:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.0

CTPH (ssdeep):
6144:JwUG/J/bSxosKjuSX2FzqDU7OBLrAUaETKahD1:iUC/bSX+X2FU1BL8UabahD1

Entry address:
0xB0FA0

Entry point:
60, BE, 00, 50, 47, 00, 8D, BE, 00, C0, F8, FF, C7, 87, 98, 00, 08, 00, 31, DB, C2, DD, 57, EB, 11, 90, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8914  (probably packed)

Code size:
244 KB (249,856 bytes)

The file codec.exe has been seen being distributed by the following URL.

Remove codec.exe - Powered by Reason Core Security