vidsplitter.exe

VidSplitter

GeoVid

The program is a setup application that uses the Inno Setup installer. This is installed with VidSplitter. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
GeoVid

Product:
VidSplitter

Description:
VidSplitter Setup

MD5:
871e7266f7230e07fb7b8c3766b1ca4b

SHA-1:
265f70ea1d87f3cb71e2e9fcc18730a99086603e

SHA-256:
c8a392eec4060e7924366e471c9d85e9f82f5321328c786149cb358188c80f97

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 9:43:38 AM UTC  (today)

File size:
11 MB (11,551,487 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Inno Setup

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\vidsplitter.exe

File PE Metadata
Compilation timestamp:
6/20/1992 6:22:17 AM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:fmSA3gqpUhIwyMu/4OLq9XJBvegsaX9tRe1GwDuTzvHSaW8hk3aQ1EArz2yBn8R2:f4QqpUCyI4Oe9X3vZpX77yEyR8hkqQ1t

Entry address:
0x9A58

Entry point:
55, 8B, EC, 83, C4, C4, 53, 56, 57, 33, C0, 89, 45, F0, 89, 45, DC, E8, 6E, 96, FF, FF, E8, 75, A8, FF, FF, E8, A0, CA, FF, FF, E8, E7, CA, FF, FF, E8, 0E, F3, FF, FF, E8, 75, F4, FF, FF, 33, C0, 55, 68, 0B, A1, 40, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, D4, A0, 40, 00, 64, FF, 32, 64, 89, 22, A1, 14, C0, 40, 00, E8, 9B, FE, FF, FF, E8, 02, FA, FF, FF, 8D, 55, F0, 33, C0, E8, AC, D0, FF, FF, 8B, 55, F0, B8, E4, CD, 40, 00, E8, 1F, 97, FF, FF, 6A, 02, 6A, 00, 6A, 01, 8B, 0D, E4, CD, 40, 00, B2, 01, B8...
 
[+]

Entropy:
7.9998

Packer / compiler:
Inno Setup v5.x - Installer Maker

Code size:
36.5 KB (37,376 bytes)

The file vidsplitter.exe has been discovered within the following program.

VidSplitter  by GeoVid
Publisher's description - “Do you have large video files and want to split to small pieces in order to record them to several CD or DVD? VidSplitter is that you are loking for video splitting.”
www.geovid.com/VidSplitter
About 3% of users remove it
 
Powered by Should I Remove It?

The file vidsplitter.exe has been seen being distributed by the following 14 URLs.

http://gsf-cf.softonic.com/265/f70/.../file?SD_used=0&channel=WEB&fdh=no&id_file=46713&instance=softonic_es&type=PROGRAM&Expires=1453250784&Signature=f-Phu3EQUPWQ8LwKWeRj6kcxo-j2wfZJ9wjksoGh9W33ltG2OUZRRtOHYU44PvOu2OjdEaCe3Ffc8o3FX4BCJ-G4Jf-OrsWGYYiq~XikJj7Vs2t~axsdzcmLQPxH6taZGzJmsvt3Zw~WmwTXBpMQ6MVb8QwyukQHEuTcNApLW6Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vidsplitter.exe

http://gsf-cf.softonic.com/265/f70/.../file?SD_used=0&channel=WEB&fdh=no&id_file=46713&instance=softonic_es&type=PROGRAM&Expires=1428318287&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=QuCu73S2B3nmZ~nv2AdoGWUILBOoX7pHQsqgurJ1mB5LxJZ7oOMDiDnBqp9I9fc0mvbmxsopnlgJervadl9a73qgcJznh5-V9~D6srGU0Fw3tPAqyVuoo2OJK4m9sLezE1H2piwdhDZ4fofg0TXeSlKYwBW7UXvy0GFsKbbWfjU_&filename=vidsplitter.exe

http://gsf-cf.softonic.com/265/f70/.../file?SD_used=0&channel=WEB&fdh=no&id_file=46713&instance=softonic_es&type=PROGRAM&Expires=1447073026&Signature=XXKxbGrVCsXynWBb4Cxgb4kVXl5oGqqBHt2YX2h5b6qWLA8o0FOmRiqaSm54fMFI9DBN2RIAmMvXL03J7GDampYWAZh~OYBlCi8WJntJiRwWUv70d-tXwy6A3M7OUzjonDoXtBgeBSUkn3Cn9gpzEwXRKcGui9yu7GadQd2lxkA_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=vidsplitter.exe

http://gsf-cf.softonic.com/265/f70/.../file?SD_used=0&channel=WEB&fdh=no&id_file=46713&instance=softonic_es&type=PROGRAM&Expires=1422005661&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=QEOjYNiuwzqNrk4W9tvuNDt90XYUDcy0JSLl6HrktrqeI97QVyhIy9v68DhTqVs3q2iTy-MSyUFDascF0aA4QQir798lQ4SMWkmtDBjhPxtwYZk8QGMlGZ~kQPULvEDxFN9GknmNoDoAn037kzdRcxViktL807nSJYvKpQubi0E_&filename=vidsplitter.exe

http://gsf-cf.softonic.com/265/f70/.../file?SD_used=0&channel=WEB&fdh=no&id_file=46713&instance=softonic_es&type=PROGRAM&Expires=1425359920&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Dls-n0wEGIZjBw3YqxKpXtOleZSYoo38LfMkdC4geUeuh7thgCkQkTxU5D7~7chrd4G13A78L50Hd23oJP-SCIL5x5K2O6dsR8LPsfafdx303ppb1S54CPR8meOJXhbiL3R2BpzdtSo6lEkERCK2eertBcSxDOdylQkUXaym-BI_&filename=vidsplitter.exe

Scan vidsplitter.exe - Powered by Reason Core Security