fvd-video-converter.exe

FVD

The application fvd-video-converter.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The file has been seen being downloaded from fvd-converter.com.
Publisher:
FVD

Product:
FVD

Version:
3.0

MD5:
96288685c8d4094e4fc0af981c9faf56

SHA-1:
acacc7df667e9cc4ff179f7654f8bf431ea1b01c

SHA-256:
a1cf6475906118bb3080716a154ae96c8eec163247d35f39b9a906ff013415e4

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Analysis date:
11/23/2024 2:20:10 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2013.11.23

AVG
MalSign.Generic
2015.0.3486

Baidu Antivirus
Trojan.Win32.OutBrowse
4.0.3.1452

Comodo Security
Application.Win32.Agent.~BRO
17316

Dr.Web
Adware.Downware.1336
9.0.1.0122

ESET NOD32
Win32/OutBrowse
8.9085

Fortinet FortiGate
W32/OutBrowse.D
5/2/2014

Kaspersky
not-a-virus:Downloader.NSIS.Agent
14.0.0.3927

Malwarebytes
PUP.Optional.Smart
v2014.05.02.03

Vba32 AntiVirus
Downloader.OutBrowse
3.12.24.3

VIPRE Antivirus
OutBrowse
23632

File size:
573.3 KB (587,029 bytes)

Copyright:
© FVD

Trademarks:
FVD

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\fvd-video-converter.exe

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:fd2ArFBW4zcfmQT5XxrxuiABXpf3PKk9hxsesWj7TlalYAyBMJM:fd3rFB5jK5XdlAbfXhllalhyau

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file fvd-video-converter.exe has been seen being distributed by the following URL.

Remove fvd-video-converter.exe - Powered by Reason Core Security