vpsetup.exe

VideoPad

NCH Software

This is a self-extracting archive and installer. This is installed with multiple programs including VideoPad Video-Editor and VideoPad Video Editor. The file has been seen being downloaded from www.downloadpresentcity.com and multiple other hosts.
Publisher:
NCH Software  (signed and verified)

Product:
VideoPad

Description:
VideoPad Video Editor

Version:
3.29+

MD5:
c2f8786508b69b817b8dd34066be576c

SHA-1:
b67c7980d13d0ce300158d9e2bf18d4eee6d9894

SHA-256:
cbadb5d2130c675fb45e64e87af153fa9af0a5c7b118ab1b0c6e02a06ed373d7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 1:40:33 AM UTC  (today)

File size:
5.8 MB (6,083,640 bytes)

Copyright:
NCH Software

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\users\{user}\appdata\local\temp\vpsetup.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/19/2013 5:00:00 PM

Valid to:
8/7/2015 4:59:59 PM

Subject:
CN=NCH Software, O=NCH Software, L=Canberra, S=Australian Capital Territory, C=AU

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6A560820FA3E9AD8E5411734B1D40AD5

File PE Metadata
Compilation timestamp:
12/9/2013 9:05:55 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
98304:fKFBvzodLvTwbweNJzBV/ny20jjs42IN4SqMFUHVwf+j3t37ZFQEQYghdSfBM:yjzKvBEBV/ya42IN4OyHV5h37ZFIye

Entry address:
0x21D8

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, FC, 16, 00, 00, 53, 56, 57, E8, 03, FF, FF, FF, 33, DB, 3B, C3, 89, 44, 24, 14, 0F, 85, DF, 03, 00, 00, 6A, 06, 53, FF, 15, 88, 10, 40, 00, FF, 15, 4C, 10, 40, 00, 68, 6C, 14, 40, 00, 8B, F0, E8, CB, 03, 00, 00, 85, C0, 74, 10, 68, 7C, 14, 40, 00, 68, 80, 14, 40, 00, FF, 15, 00, 10, 40, 00, 68, 90, 14, 40, 00, 8B, C6, E8, AB, 03, 00, 00, 3B, C3, 74, 49, 83, C0, 0E, EB, 08, 66, 83, F9, 20, 75, 0A, 40, 40, 0F, B7, 08, 66, 3B, CB, 75, F0, 0F, B7, 08, 33, F6, 66, 3B, CB, 74, 20...
 
[+]

Entropy:
7.9996

Developed / compiled with:
Microsoft Visual C++

The file vpsetup.exe has been discovered within the following programs.

VideoPad Video Editor  by NCH Software
From the EULA: " During installation of this download you will be given the option to install closely related programs from the NCH Software suite. These are optional and you can select what you want depending on your requirements."
www.nchsoftware.com
20% remove it
VideoPad Video-Editor  by NCH Software
www.nchsoftware.com/videopad/de/support.html
About 1% of users remove it
 
Powered by Should I Remove It?

The file vpsetup.exe has been seen being distributed by the following 7 URLs.

http://www.downloadpresentcity.com/WUVoKdKBmCv_dZp8GWBXcZLg8KWLkKZFZ_c_Ng3UdxLTmme39K3x44sp8d7ZTBHEAJ2u_c8xtSDmG_I_gf0yqgVZZBGClaXv21EKQpbDcgyqe26e7nwvEEv tNLjBRalQLlFh NEGuCN_KZZshJg6V_8vF4LSgG9WomyOim_MgzyC8gGtL68CfBDN3Yenw6EsdVy7K6q-GxkDAGTKTaoscoIu5F4R0YaxxSOIwkQO2NtiiPkk9t448GSNkZ9FYC7F9q5GuOfbuOI9VlZUGhl7c3jaaCBdd9_QNlpS0Kkes6VxC6jCl5K86SBvKRcRgjfqUyh4AlhMU_SWtGMUgaUw YAuDySd2Vs1kcSlGXb 4sUCTElDhRU29LuaHZ3xAGwhukePALngFE aPySLwk9Eun8Zw4zaEM8sUgZKLeJb wWlbyvwlCxF9 9MHvxTl WeyaxO g7v3Yze9vRgmEsVLWhhF8jp82L5 g5TJ5L0igX44SjBNGh9zBxYHiK nwT8vCUQ b6V1I3jdor8re13niDqxF5KQApaRkruA0G5F94XxpXo_acXcSUNByAqgG6vIH9HfMdF3H3OjWrGSzbGSdRkH5DFGPpoYT_tjiA9Nmpr8_tLi s8QpW34ZMlxoB9FuPeT0I5fRB4j sd6BEfdNY69Y2wEhTmZuKRa6OfTY2zk9gEj0sf0kQ_uKo9uRyGL8t5QPYSXwGmUnl9wk8apVclRKuvLnaZNgpJdwNn1gYhHE5JwbPajLEvFd5TmIlDqu_Xf1DhYmDmAfgqr4Is5SuBy4ml39kyiT_1p 1fljRpMYsdB9UqWI9fiJpUoeK9JRVkF2W5hvg9IQnUMyf9lxEzKitPusUxaddNd4S7wmSEXc7nT9cE NeznyLWdyatypkR4gElBzylNZj UrXtM A_JTRhGMPDML9LoxBPzPaT0jVrE7YCS1seT1Hs_M_C8vOL

https://dw.uptodown.com/dwn/BMBVzEOC-ICZUkoNN87CSr36orLkY0Q6rQnNTz877yIw6rQM7yuHP9YhZfArDxM5l1TA7swG1ft8zc-G9nRVRzHkgY3xvZJxQg5gqDuJ2je8RDkXqu1CNF70fxF566wU/6QDxKbIQKpZW1j8VVKToktxHqaesRiATSq8TqUssI7fCVy1epRB6h8JLa2UjBTYcVH8tnbiwHOZWu7eLLs5X0srjUL0JYCSTBg059mPHRnKGJNGP_kap8LI7kldGUoXo/xng3D7VK8zq5oL1NqISy5NUvj4j86CPCaHTkuuErxpTwAnQv9k9FflmrQEWvfst3RlVmW8RlwwkWdbSgeoznZeE-x0GNZkY5bjzupGug3SspJB1RcWYC-8nebhOb0ifN/.../

Scan vpsetup.exe - Powered by Reason Core Security