savevidsetup-r0-n-bc.exe

The application savevidsetup-r0-n-bc.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup program which is used to install the application. Infected by an entry-point obscuring polymorphic file infector which will create a peer-to-peer botnet and receives URLs of additional files to download. The file has been seen being downloaded from download.savevid.com.
MD5:
34a22a472c7593c85bc548bc5e61041c

SHA-1:
82fc508334a18ad7cf17db2f14ed4720dd18ab9f

SHA-256:
4f89ed6df037199e0d38fa1b123073f330957e836511f750dd41b1b029e69c6d

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
12/26/2024 6:45:19 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:SaliCode
160126-1

AVG
Win32/Sality
2015.0.4477

Dr.Web
Win32.Sector.30
9.0.1.05190

Emsisoft Anti-Malware
Win32.Sality
10.0.0.5366

ESET NOD32
Win32/Sality.NBA virus
7.0.302.0

F-Prot
W32/Sality.gen2
4.6.5.141

Kaspersky
Virus.Win32.Sality
15.0.0.562

McAfee
Program.Artemis!A76943778310
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.213.5530.0

Norman
Win32.Sality.3
03.12.2014 13:20:04

Sophos
Virus 'Mal/Sality-D'
5.23

File size:
2 MB (2,086,440 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\savevidsetup-r0-n-bc.exe

File PE Metadata
Compilation timestamp:
2/25/2012 12:50:04 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:m2CQ7uk47xAOyPOSBfVE0xbvPBCBqWCJQc:mwukyxAOyPtB2OvJhtJ

Entry address:
0x38AF

Entry point:
F6, C0, C6, 8D, 05, 24, CD, DC, 82, 3D, 2D, 2A, 00, 00, 78, 0D, 8D, 05, 64, 2B, D3, 02, 87, FE, F6, DE, 0F, B7, EE, 87, C9, 30, D1, 56, 69, C6, 66, 59, F5, D5, 58, 8B, EF, 8B, F0, 04, 35, 88, E1, 33, DE, 18, CA, F7, D9, 3D, 7B, 6E, 00, 00, 71, 02, FE, C0, 88, F1, E8, 98, 00, 00, 00, F6, C7, EB, 81, CF, D9, 95, 30, 72, F7, D6, FE, CC, 76, 10, 8D, 3D, 2B, 16, 8B, 55, 85, CB, C6, C1, CD, 8B, C0, 0F, BF, F9, BD, 5D, 8F, 05, 00, 0F, CE, 81, F5, 3A, 64, 00, 00, 81, FA, 0D, D0, 00, 00, 78, 0D, 69, F3, 86, 23, B5...
 
[+]

Entropy:
7.9841  (probably packed)

Code size:
29 KB (29,696 bytes)

The file savevidsetup-r0-n-bc.exe has been seen being distributed by the following URL.

Remove savevidsetup-r0-n-bc.exe - Powered by Reason Core Security