installbrowserbuttons.exe

Dennis Nazarenko

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application installbrowserbuttons.exe by Dennis Nazarenko has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Dennis Nazarenko  (signed and verified)

MD5:
ae8286973bbda61da14fe84e10877e9d

SHA-1:
32b6d4d6b702bfa596dca89087a0fb75967113d9

SHA-256:
42e56a7a481aac6841809cddb020f2a3a1f0d427d6b30809610d62e01d165fcd

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/17/2024 3:15:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
16.10.12.11

File size:
577.3 KB (591,112 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\tidy favorites\installbrowserbuttons.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
11/1/2008 5:00:00 PM

Valid to:
11/2/2009 3:59:59 PM

Subject:
CN=Dennis Nazarenko, O=Dennis Nazarenko, POBox=15A, STREET=Jovtneva 7A, L=Vishneve, S=Kievskaya, PostalCode=08132, C=UA

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
009CA1956F3A54A095BA9D02BC02272CFA

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
12288:Qlh4NKD1octvkeursVqI3O2ptvvFvZGRUb6:QlqNsktoVhOIvZGRUb6

Entry address:
0x7EF74

Entry point:
55, 8B, EC, B9, 07, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, 53, A1, A8, 1E, 48, 00, C6, 00, 01, B8, 1C, ED, 47, 00, E8, BD, 7F, F8, FF, 33, C0, 55, 68, 19, F3, 47, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E0, 33, C0, E8, FD, 3E, F8, FF, 8B, 55, E0, 8D, 45, E4, E8, A6, 63, F8, FF, 8B, 45, E4, 8D, 55, E8, E8, FF, D3, FD, FF, 8B, 45, E8, 8D, 55, EC, E8, 4C, D2, FD, FF, 8B, 55, EC, B8, 88, 49, 4A, 00, E8, F7, 61, F8, FF, 8D, 45, DC, B9, 2C, F3, 47, 00, 8B, 15, 88, 49, 4A, 00, E8, 68, 64, F8, FF, 8B, 45, DC, E8...
 
[+]

Entropy:
6.6117

Developed / compiled with:
Microsoft Visual C++

Code size:
505 KB (517,120 bytes)

Remove installbrowserbuttons.exe - Powered by Reason Core Security