coolmp4tompegconvertersetup.exe

Cool MP4 To MPEG Converter

A Software Plus

The application coolmp4tompegconvertersetup.exe, “Cool MP4 To MPEG Converter Setup ” has been detected as a potentially unwanted program by 12 anti-malware scanners. This is a self-extracting archive and installer, however the file is not signed with an authenticode signature from a trusted source. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
A Software Plus

Product:
Cool MP4 To MPEG Converter

Description:
Cool MP4 To MPEG Converter Setup

Version:
1.0

MD5:
1837a114301a7270732c82a5800abdd6

SHA-1:
e6eb0e38d9735abc12903338bd4bd8c0d7766d3b

SHA-256:
94b63c1c86f3ef8b4f33ef7caab798c699f9352a50eb28eac495bd2e20719364

Scanner detections:
12 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:45:03 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
ADWARE-Tmrg.Gen
2.1.4+

avast!
Win32:Relevant-S [PUP]
2014.9-150412

AVG
RelevantKnowledge
2016.0.3142

Baidu Antivirus
Adware.Win32.RK
4.0.3.15412

ESET NOD32
Win32/BundleLoader.B potentially unwanted
9.11425

Fortinet FortiGate
Riskware/RK
4/12/2015

K7 AntiVirus
Riskware
13.202.15486

Kaspersky
not-a-virus:WebToolbar.Win32.RK
14.0.0.2204

Malwarebytes
PUP.Adware.RKN
v2015.04.12.04

McAfee
Artemis!1837A114301A
5600.6798

Sophos
Generic PUA OG
4.98

Trend Micro House Call
TROJ_GEN.R047H07C315
7.2.102

File size:
3.3 MB (3,450,631 bytes)

Product version:
1.0

Copyright:
Copyright © 2008-2009 A Software Plus

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\coolmp4tompegconvertersetup.exe

File PE Metadata
Compilation timestamp:
1/30/2013 8:21:56 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:pUk0lrjpulSbAn4st9W5QhllT3nFptbwBL:pWlpu5U5yTXlwh

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9874

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file coolmp4tompegconvertersetup.exe has been seen being distributed by the following URL.

Remove coolmp4tompegconvertersetup.exe - Powered by Reason Core Security