freevideodub.exe

Free Video Dub 2.0.15.1031

DVDVideoSoft Ltd.

The application freevideodub.exe, “Free Video Dub 2.0.15.1031 Setup ” by DVDVideoSoft has been detected as a potentially unwanted program by 2 anti-malware scanners. The program is a setup application that uses the Inno Setup installer. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
DVDVideoSoft Ltd.   (signed by DVDVideoSoft Ltd.)

Product:
Free Video Dub 2.0.15.1031

Description:
Free Video Dub 2.0.15.1031 Setup

Version:
2.0.15.1031

MD5:
b21543d7c7d2119a3369f9fb8432e09b

SHA-1:
391421278af9a3a4238ba276ca04f18ec820c50a

SHA-256:
8f89e4ab7684748b78221078d99624286c2071f88aa460f4a818e3edc8945e8f

Scanner detections:
2 / 68

Status:
Potentially unwanted

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
12/28/2024 6:12:11 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
8.9615

Reason Heuristics
PUP.OpenCandy.Installer (L)
16.11.29.23

File size:
16.5 MB (17,276,280 bytes)

Product version:
2.0.15.1031

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Common path:
C:\users\{user}\downloads\freevideodub.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/16/2010 2:34:18 AM

Valid to:
7/16/2013 2:34:16 AM

Subject:
E=question@dvdvideosoft.com, CN=DVDVideoSoft Ltd., O=DVDVideoSoft Ltd., L=Roseau Valley, S=Dominica, C=DM

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000129DA2C9832

File PE Metadata
Compilation timestamp:
12/20/2011 10:16:50 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
393216:xBqfUQrOJjUdOCeN1h3RbldhVtyDT8seYDfxyuoNt9+B2hCcT:xBqfEoXeN1zldhWDT8snjxyuoNtO2HT

Entry address:
0x16478

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, B0, 52, 41, 00, E8, AC, 03, FF, FF, 33, C0, 55, 68, 45, 6B, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 01, 6B, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, AB, 41, 00, E8, 4E, EC, FF, FF, E8, F5, E7, FF, FF, 8D, 55, EC, 33, C0, E8, 7F, 84, FF, FF, 8B, 55, EC, B8, AC, D6, 41, 00, E8, E2, E9, FE, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, AC, D6, 41, 00, B2, 01...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
84 KB (86,016 bytes)

The file freevideodub.exe has been seen being distributed by the following 34 URLs.

http://dw.uptodown.com/dwn/DoufzowQHvKh_7YFmj1pIwH506QM0vwhAjsyNRuUplzxwTkv_ZLoo6lIk6TpD0GwGMNUj4iHxG81yJltVdn7cEiIqBq9dwxLznRVJ9o_EE0ZaDbgbrKiuN7RUzgEoLwy/kvVrRMVNAhPQ14cvSz3ARykSgpDe2MyHQc9InR3D-ysLgb3xu6qZi-6rr4SUpraqIdVwi3bra63FKpBXZfCmG_44w_FyBN4wBB-7hoOAn_sQ7JbbLMaClIACwEsB74Yl/p9GCG_1zZNklw1UFZU1NiqIp5buLtM6Bo_RAf6qc0HD6Xil8djSN7AE_jzz2YNA1q7DN2LHOSC5QuvgxcDJ6DaFff9tEf7OjmNUR0VHJ5Fj08TlW__NPWhgYSrExs3K-/.../

http://dw.uptodown.com/dwn/jAf3fYrQfkdsFX6DEGc0o6XiA0px6E2Ne7YjppadtDF5JGXriWQAvuXtidnGppZkStEbqsp-RrzNMfVPmkzedSNvFPcp2VQHeT_XxAyZzW_KAG-xcUHdFZPYgYzxGqdv/.../

http://dw.uptodown.com/dwn/Cea0yTAOp0boHVj7YlxYa_sXXxhUfRFqwfwLaEvV5xVHPOSCfMPXstTP55RNk5RjA2e8ym_nzoN0JG5lWUgtAgqAzYvVqFTycW7Qu59bIdiCER03E1ypZe4J6N_tKCfM/NOsYjAnILri-WEXO6TYc3Qruq5_EAPxopnf2IQD2Fi6DD6gx1pL6fvnZS4qQGqXj4xbuJG2ZcKI5tTfWmvZ56FPADYi4n8Lhg1NagKgGiQLYZUVj5yusYCEZ3cKaG_58/.../

http://dw.uptodown.com/dwn/ODI66Sk830aKRVw8-VxaCXZiCfrQAOeHv7_fzwV3T6q6BnmWngD2_CwsTdi1BmBe1de_bS5XY96EgHPGP58I_38JTELlKFU3rzRoFpBy4rZJCDdxEo86y7StDdGQk-Hh/hWH6KB_msqAgNlFcAmbRHTUqvyQgy-bj-z4LRZ747jgjM8QujI5Mj6MsdtKBFWbqacf0aZzNBiQreoXh8YQ-7bxYZRSjIBYtvTkZDNhvbHaodBH-ck3wvMH5MzauAsJc/-PB-A_O6bBHIGyzvO5NZKrnh48JVInFZuoaR3MsWN5PFPtpVjzIuwsLYlS54iZbHqJ05ItcuJed6FvjWhmEVoQ8FrZdrMXTOA-NqKZX_TVYQvZG3sV6pOdVGmlQAwq1g/.../

http://dw.uptodown.com/dwn/HkRlpRPtt-_9rGzJqD3qAZwKhFTReHK-EWk1HfbNm4Mm81e2JrRqoQhRMdIRn715yZ0cfAYNptuws1FfT3Cs9AjBlQ1nF1yDYF_eFDm8X7JGQ_dN85T96Q2uEIT5_Z-Z/NvOHAvoTEZ0oVraEMIfLU3RYPRYlAkdvb73I6DjIvaD98PWVzTEXrCnbFU5SJIKv_0TFdr0I9ug1tytHp4ni8_hkiafZrbgcj2TWgw4Rwwq5gxRm7x4wFrUDeKEzZYJq/nmagQgLx5nTeL_AIcfgTTCTsHeBztpAy81V70zWsoUUhuVunapsomeKmHciYwVoZfa8ocM74KRq6D_WRaAP-5rVDBjuFJlJpHePRFiEJRspQRQladRj0rM5F9VzwDkuC/.../

http://dw.uptodown.com/dwn/m-d0n_8xntaMzxnP0DzSyXAQahn2wT27SCGjJnn6_IyzzgUF-YnBZ9tfnsm4otxJ2rfEVBDRzHeKNrwtGcI5A0T33Iw46TV4ln7KSLEhwwRBXfoNVa7hckjTYRjY8XHq/mCQHHULc533T_YB_8WdzMtVHfQkiXt8dj1UozhrRj_nWXxmN4aao8PgzVGWuFBOmpDihS_GcNm8azJCsZmw1zSoochHwK1XF5a6UCD3MBvEh8IbR9c-RBCZCjTjPlhK8/K8EyhFYZ6qItB7G3S8jheuzDoYnTroVrXuaoK3qZvs-HlX-UL8nC35nRAS921c0A-AHtdPDrMm8AG2KWN-KhqmFEsCSGsifXGXxo2whMEjSgAlGwWLUa8L2N0_hEGV8Y/.../

http://dw.br.uptodown.com/dl/1441758162/.../free-video-dub-2-0-15-1031-es-en-win.exe

Latest 30 of 34 download URLs

Remove freevideodub.exe - Powered by Reason Core Security