atube_catcher.exe

aTube Catcher

Diego Uscanga

The application atube_catcher.exe by Diego Uscanga has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This file is typically installed with the program Portable Start Menu 3.2 by aignes.com. This version of the installer will bundle the Ask.com Toolbar, a potentially unwanted web browser extension. The file has been seen being downloaded from dw.uptodown.com and multiple other hosts.
Publisher:
DsNET Corp  (signed by Diego Uscanga)

Product:
aTube Catcher

Version:
3.8.7943

MD5:
57dd30d91a914ed5324f0e3f1fa26e8f

SHA-1:
f330183ef347f5e5aa80882acf35f4029fd4cc60

SHA-256:
de012a971af4e2aa6c7bd85415a7e76016f8c6a7af98e8efe7550326904588a6

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
Bundles that Ask.com toolbar as a third-party offer, a web browser extension that may modify a user's search and home pages.

Analysis date:
12/26/2024 4:21:34 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.WindowNM
14.03.31

Dr.Web
Adware.Downware.1417
9.0.1.090

ESET NOD32
Win32/Bundled.Toolbar.Ask (variant)
8.9618

Malwarebytes
PUP.Optional.Spigot.A
v2014.03.31.07

McAfee
Artemis!57DD30D91A91
5600.7174

Reason Heuristics
PUP.DiegoUscanga.N
14.5.10.12

Trend Micro House Call
TROJ_GEN.F47V0325
7.2.90

File size:
16.3 MB (17,109,800 bytes)

Product version:
3.8.7943

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/26/2014 9:00:00 PM

Valid to:
2/26/2017 8:59:59 PM

Subject:
CN=Diego Uscanga, OU=Individual Developer, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=No Organization Affiliation, L=Huixquilucan, S=Mexico, C=MX

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3891D1349D41A2C39A519812D8C15FAC

File PE Metadata
Compilation timestamp:
7/14/2013 5:09:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:4wBlqQ9rmdFD6RFACcS/0Ok9JPLQcghhQvoLbMjlCubg1HIffZmkD:4SlqQgdFDvskTLxg2cM0/YZB

Entry address:
0x324D

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 3F, 42, 00, E8, 8B, 2D, 00, 00, A3, E4, 3E, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, F4, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 36, 42, 00, E8, 35, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 23, 2A...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file atube_catcher.exe has been discovered within the following program.

Portable Start Menu 3.2  by aignes.com
www.aignes.com
About 5% of users remove it
 
Powered by Should I Remove It?

The file atube_catcher.exe has been seen being distributed by the following 20 URLs.

http://dw.uptodown.com/dwn/fMWeJ069ECzl2sBCoFtvEVcMdnwT3KO1DFZU09vFw3VwPtz4WHwgnNg3KlOxPEqL1ZnD3zsad9jiTxJZ3ij_XQhyYw-dnUlnlHcryg_TAAwf0BABk_kF7AJGYeZS-liE/1R5Wwc0dB7H0BMMjeh_y6UxTSjer2CQ263zmFBZ1IfqNg1D_SkIIBLCMkeoaxAKeUocIEsebnrYwJPTtYGeVgIWTV3OG1n2n3Rz8kR2G2NEyYa9m7xo-2iWGFTFkXp10/oYpTD6Di7DvU1ha5nYE57iSBj5JvQoVMGvSZHCCDFSHnEj3DcDXMNrsENrsZEsbKhMhskzAIeJP9unnjRIPwdV16AF0W-AsvtfvU9S1n7XTxlRPIlyTMYR8MqL7c_BSC/.../

http://dw.br.uptodown.com/dl/1424429165/.../atube-catcher-3-8-7943-es-en-br-fr-de-it-cz-cat-win.exe

http://gerenciador.nzs.com.br/programas/urls/iron/.../atube-catcher.exe

https://dw.uptodown.com/dwn/hPeGXYG4D3wgQkdK4IF4eBhLSC4oDI7VsBj0ycKZ70TS5rqAkD9Jaz1EGPklC_XuthkGRuRxEJD9mVYD_ev2QFW5whTbIAKBPwlstGeFYVlWzcDcVvgd2NUSpWyX58PM/5-dO9LrD3qZL1hIOCsZfupoLol_o_UjFlk6H3Vfguab6JGODaEjiR4IfwTvGG8Zr-A1Vx8TAbd79MQtVyvDI5QmR6YRLmQXoBO_eiPRpJck2qOj1fbSPSVOVYcf7qV-R/Wbn2cDk0-5FsOXqSh2iLn2pzznEdJ0B4s4SQUSavm7LkAnhddelQjKwL7dnRmTHrLofEjLP_FITI7qsI3OfRx1d5WXskfzfCUwOA1oKp4IXUfcNccKo5Jzz1l2Jzd7sJ/.../

https://dw.uptodown.com/dwn/ietwDanYF5rcWlbzEAb2EUZ57eAatCUyvvVHZUQUo-5YxoEUbk9_7uMIZ0hX7ixjCcbgUj0RuyqnT2XyT7roDESJ7n8mYPv3l_A377t3i_CutGW7gd6wYFWK-5Q2Iu76/n_OkjN6wYZeDNE1WY4QI6zTr_RE8E3jT-H8aFMtUa9zYLXWS0EVad7_ns6IRguR3tCXtZUd-LC94996mhk9BeNq0Rw4K975EJ0Lps59uVXx9W542LTcs6BHiwxrUbp9l/VYPt9ZxLQ-mJVIOkF13gyTyAUmviAybJJ53x-P9sdGL9665NbOgVBHhmSGBI1HjjGfQnrtxWZJ0WMqy7NOXZJ4_hrAglGnxSpfPLBPCPfJu3nH46_-fl3Wczj7IBeWDE/.../

https://dw.uptodown.com/dwn/Dyv34Tz-q7LvCbwlciAp7wPn7nP3Dum4Xf7J6Vdi_eMEhN0PexCYaCSyhZbIPpJbEqhYPZiG1UaFtEuG87gdPv5UOgdutjr2mJqlQ2AbZnZ0okXcVKTZDGAcmTq4yG10/fWbFw91BWxhxBP8z-OGFC_cOxhHes5L2E3NTfb5DRVCi6zbvKyTkCMg3TEwTM72u8RKYFACgl2aZJFdCIRag6wWe_KXLNKktmmD70fGjqgGxWKgTOzQdDNJ1jckGQzra/xIzRgEuWakvC2xXJX9Ky5stlTH8MYuhq7-SJ-EVbk7Wt9seoENJBQCrg7fPVdtpcgjRRiaJGW-_WkX1K-6Ktj0y8EeFP-pFPqHJ_cMwWiAYup4KFWj3aZw8g-jx-ie5Z/.../

https://dw.uptodown.com/dwn/dJI_a2bAbTCzVvFqrRSteVjlQFM4SFBELDsn_MDSH-3QE6Hd7Jo5v5ecgNYcpotSII6NVCr5GdudTveB22yhQn8G_08s5DMrVz0qZarwW_sXF_rXOVhllmSz5SuWS4C6/P89CT-43GUtA9ju3fjz6AqSCqcWh5Yf_jgka7MM5SsAZsAEHAVPUpc8lpZEvtSD9qHakM7sUAmAWAIW2wWetUU5k4RtSG5HjtJgwd8qXxnZlQfCLJ8qWGeSmh6yZn1no/JOCmLsMJ5Stfi238WWpnX-5p3cxLU4vYgmSqux3zMTnXCEBoICJsn7NkFakrfKHNqJxp9RqxCbPvEzkKgPIc-xrKfm2Wp5bU5NIhG2M08gmlWQcswO8Jf5na4AQ8Mdhb/.../

Remove atube_catcher.exe - Powered by Reason Core Security