cooldattomp3convertersetup.exe

Cool DAT To MP3 Converter

A Software Plus

The application cooldattomp3convertersetup.exe, “Cool DAT To MP3 Converter Setup ” has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
A Software Plus

Product:
Cool DAT To MP3 Converter

Description:
Cool DAT To MP3 Converter Setup

Version:
1.0

MD5:
d428759daa34bf9c691f01e3c7f59259

SHA-1:
9335c105b768c694752a60726538df9f7599e47c

SHA-256:
b04998cfa6846bad86b051ff324aaf786ea56b0ee204884378b9a5e99475c6d8

Scanner detections:
11 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:39:51 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADSPY/NaviPromo.J
7.11.150.252

avast!
Win32:Relevant-S [PUP]
2014.9-140716

AVG
RelevantKnowledge
2015.0.3412

Baidu Antivirus
Adware.Win32.RKToolbar
4.0.3.14716

Fortinet FortiGate
Riskware/RK
7/16/2014

K7 AntiVirus
Riskware
13.178.12171

Kaspersky
not-a-virus:WebToolbar.Win32.RK
14.0.0.3555

Malwarebytes
PUP.Adware.RKN
v2014.07.16.01

Qihoo 360 Security
Win32/Virus.WebToolbar.9c5
1.0.0.1015

Sophos
Generic PUA JD
4.98

Trend Micro House Call
TROJ_GEN.R0CBH07DK14
7.2.197

File size:
3.3 MB (3,448,325 bytes)

Product version:
1.0

Copyright:
Copyright © 2008-2009 A Software Plus

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\cooldattomp3convertersetup.exe

File PE Metadata
Compilation timestamp:
1/30/2013 8:21:56 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:ME0OQIryt3W3KjPQU7NtyQLPVdDJvwJJZBL:MVOQnJjYs9NdDJoJJZh

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9874

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file cooldattomp3convertersetup.exe has been seen being distributed by the following URL.

Remove cooldattomp3convertersetup.exe - Powered by Reason Core Security