freecordertoolbar.exe

Freecorder Toolbar

Zugo Ltd

The application freecordertoolbar.exe, “Freecorder Toolbar Installer” by Zugo has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from components.zugo.com.
Publisher:
Zugo Ltd  (signed and verified)

Product:
Freecorder Toolbar

Description:
Freecorder Toolbar Installer

Version:
5.0.0.0

MD5:
0d53df45edf992f2b9931ea8a65ae111

SHA-1:
f2863ed5908a3a0428476f1ecf0277c78f1e8d25

SHA-256:
3de4f5c95622874a0d04ce86ccffa22c8217fcbdc6ce7e9eae5de7de58456940

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 12:41:41 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Zugo.Installer (M)
16.5.13.7

File size:
1.1 MB (1,111,704 bytes)

Product version:
5.0.0.0

Copyright:
© Visicom Media Inc. (License)

Trademarks:
, All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\freecordertoolbar.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/27/2011 4:00:00 PM

Valid to:
1/27/2013 3:59:59 PM

Subject:
CN=Zugo Ltd, O=Zugo Ltd, STREET=PO Box 36, STREET=1st Floor, STREET=37 Broad St., L=St Helier, S=Jersey, PostalCode=JE4 9NU, C=JE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
46241CDE5C7B500B51C5F1328228F2A9

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:xJL7i2MswrsPbEdCBghjcrisD7SXCh5pa8ASwBsTBr6P:T7ZDwIMCwoHD+Xs0FSRy

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9742

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file freecordertoolbar.exe has been seen being distributed by the following URL.

Remove freecordertoolbar.exe - Powered by Reason Core Security