pdfviewersetup.exe

Vivid Document Imaging Technologies

The executable pdfviewersetup.exe, “PDF Viewer for Windows Setup ” has been detected as malware by 10 anti-virus scanners. The program is a setup application that uses the Inno Setup installer, however the file is not signed with an authenticode signature from a trusted source. The file has been seen being downloaded from www.win7pdf.com.
Publisher:
Vivid Document Imaging Technologies

Description:
PDF Viewer for Windows Setup

Version:
1.0.0.220

MD5:
cf51c96cb1e6d12f65d5841db1ac5fcb

SHA-1:
1e3ab9e6857a41da5c6592cd0ce70d272ee9a0af

SHA-256:
16049abc77dcd4f6731cfab69d48b811118805df52603aa0f662531931fab250

Scanner detections:
10 / 68

Status:
Malware

Analysis date:
12/27/2024 5:06:17 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Vitro
160518-2

AVG
Win32/Virut
2015.0.4568

Dr.Web
Win32.Virut.56
9.0.1.05190

Emsisoft Anti-Malware
Win32.Virtob.Gen.12
11.5.0.6191

ESET NOD32
Win32/Virut.NBP virus
8.0.319.0

F-Prot
W32/Virut.E.gen
4.6.5.141

Kaspersky
Virus.Win32.Virut
15.0.0.562

McAfee
Virus.W32/Madangel.b
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.221.795.0

Norman
Win32.Virtob.Gen.12
19.05.2016 05:17:13

File size:
959.3 KB (982,302 bytes)

Copyright:
(C) Copyright 2009 Vivid Document Imaging Technologies

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
English (United States)

Common path:
C:\users\{user}\downloads\pdfviewersetup.exe

File PE Metadata
Compilation timestamp:
1/4/1996 6:59:57 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:42UBGLHW3a23JK0x2GHJWIqS5yxRT9kasnrrfVNMj+WNNynWD6YDKm:42UyHGRpHRSJRyrDDMKOMM6qH

Entry address:
0xF6202

Entry point:
8D, 00, 83, 3C, 24, FE, 77, FE, 8D, 64, 24, CC, 60, 87, E9, B3, 0D, 83, EC, DC, E8, 03, 03, 00, 00, 4B, 66, 4B, 90, 75, FB, 4A, B6, 65, F8, FF, 73, 3C, 59, 81, E9, FD, FF, FF, 7F, 8B, C5, F6, D6, 73, E6, 8D, 13, 90, 90, 81, D9, E6, 13, 00, 00, 71, DA, 46, 29, CA, 90, FF, B4, 19, E4, 13, 00, 80, 83, C4, 04, B9, 52, C5, 76, 8C, 8D, 3B, 66, 81, 44, 24, FC, B0, BA, 75, BC, 80, CC, 5E, F5, 68, 9D, DB, FF, 59, E8, D9, 02, 00, 00, BA, 6E, 44, 1C, 1F, 8A, E4, 89, 74, 24, 44, E8, 91, 03, 00, 00, 90, 89, 44, 24, 34...
 
[+]

Entropy:
7.9772  (probably packed)

Code size:
36.5 KB (37,376 bytes)

The file pdfviewersetup.exe has been seen being distributed by the following URL.

Remove pdfviewersetup.exe - Powered by Reason Core Security