coolvobtompegconvertersetup.exe

Cool VOB To MPEG Converter

A Software Plus

The application coolvobtompegconvertersetup.exe, “Cool VOB To MPEG Converter Setup ” has been detected as a potentially unwanted program by 3 anti-malware scanners. This is a setup and installation application, however the file is not signed with an authenticode signature from a trusted source. Part of RelevantKnowledge, a program typically installed via a software bundle (with the user's knowledge should they read the EULA) and will run in the background collecting and monitoring information about the user's behavior in order to build an extensive profile.
Publisher:
A Software Plus

Product:
Cool VOB To MPEG Converter

Description:
Cool VOB To MPEG Converter Setup

Version:
1.0

MD5:
de53fbdd4f2ea87fcd6f0982f8c9f38c

SHA-1:
cbd27cc79441c404ab6e81ac149a92fb9aa29ba0

SHA-256:
bb4fac99cdbc96b0afa086432d98066514484244749c92d195e6ea98092e100a

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 7:42:05 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
NSIS:Relevant-H [PUP]
2014.9-160611

ESET NOD32
Win32/BundleLoader.C potentially unwanted (variant)
10.12200

Malwarebytes
PUP.Adware.RelevantKnowledge
v2016.06.11.06

File size:
3 MB (3,097,576 bytes)

Product version:
1.0

Copyright:
Copyright © 2008-2009 A Software Plus

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\coolvobtompegconvertersetup.exe

File PE Metadata
Compilation timestamp:
10/13/2013 1:49:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
49152:VA6/KHcvGGADWudnetBSCQt3Rf+15z98uNbI0jGW51LCYh9zmaIEhsiZ6mxs+L:z/BaEtBSPRfmzXbT35VTzmIhZZRxDL

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 2C, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 16, D8, FF, FF, E8, 65, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 2B, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 50, 86...
 
[+]

Entropy:
7.9845

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file coolvobtompegconvertersetup.exe has been seen being distributed by the following URL.

Remove coolvobtompegconvertersetup.exe - Powered by Reason Core Security