deltatb.exe

Visual Tools

The application deltatb.exe by Visual Tools has been detected as adware by 6 anti-malware scanners. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from i.downloadsok.com and multiple other hosts.
Publisher:
Visual Tools  (signed and verified)

MD5:
eb2764885565b6c01cb32e5f51f213b3

SHA-1:
cc41cadbbd6ba6ed0bfdd17798b4c9f94d7955e0

SHA-256:
d7146999ff94b3ae092f3213ddf0217615f1d38798393b66778d11aae2b68eaf

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
12/25/2024 1:14:37 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.Babylon
2013.12.03

Dr.Web
Adware.Toolbar.175
9.0.1.0338

ESET NOD32
Win32/Toolbar.Babylon (variant)
7.9123

Malwarebytes
v2013.12.04.09

Reason Heuristics
PUP.VisualTools.H
14.8.7.21

VIPRE Antivirus
Babylon
23962

File size:
767.5 KB (785,904 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\deltatb.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/10/2013 1:00:00 AM

Valid to:
1/11/2015 12:59:59 AM

Subject:
CN=Visual Tools, O=Visual Tools, L=Belgrade, S=Serbia, C=RS

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
789958B0264F06055619270074AFA61F

File PE Metadata
Compilation timestamp:
3/13/2013 12:56:02 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:XSsZfDKTpv0aNjLDiIx56qQDtOZTIzOjAWe0YiZ2PADaRx6Zfuc//yTuXbdir7+:XSiGTpTLDxxwqQcqOj5eyHox6ZGmAuXr

Entry address:
0x15A7

Entry point:
55, 8D, AC, 24, 40, F6, FF, FF, 81, EC, 3C, 0A, 00, 00, A1, 00, 50, 40, 00, 33, C5, 89, 85, BC, 09, 00, 00, 53, 56, 33, DB, 57, 8D, 75, 88, 88, 5D, 87, C6, 45, 86, 01, E8, AD, 05, 00, 00, 53, 89, 9D, DC, 01, 00, 00, 89, 9D, E0, 01, 00, 00, 89, 9D, E4, 01, 00, 00, C7, 85, E8, 01, 00, 00, 03, 00, 00, 00, FF, 55, C4, 89, 85, D8, 01, 00, 00, 8B, C6, E8, FD, F9, FF, FF, 3B, C3, 0F, 85, 0A, 01, 00, 00, 8D, 85, EC, 01, 00, 00, 50, 8B, FE, E8, 35, FF, FF, FF, 8B, F8, 3B, FB, 0F, 85, C0, 00, 00, 00, 33, FF, 66, 39...
 
[+]

Code size:
11.5 KB (11,776 bytes)

The file deltatb.exe has been seen being distributed by the following 3 URLs.

Remove deltatb.exe - Powered by Reason Core Security