pandotoolbar.exe

Pando Toolbar

Zugo Ltd

The application pandotoolbar.exe, “Pando Toolbar Installer” by Zugo has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from components.zugo.com.
Publisher:
Zugo Ltd  (signed and verified)

Product:
Pando Toolbar

Description:
Pando Toolbar Installer

Version:
1.0.0.0

MD5:
48711056fa32b9e76bf6fb359ec1abcc

SHA-1:
d9d188c1e9e171ea896abf6204c6176e5b1e768f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/15/2024 12:50:44 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Zugo.Installer (M)
16.1.23.17

File size:
1020.4 KB (1,044,928 bytes)

Product version:
1.0.0.0

Copyright:
© Visicom Media Inc. (License)

Trademarks:
, All Rights Reserved

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\pandotoolbar.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
1/27/2011 7:00:00 PM

Valid to:
1/27/2013 6:59:59 PM

Subject:
CN=Zugo Ltd, O=Zugo Ltd, STREET=PO Box 36, STREET=1st Floor, STREET=37 Broad St., L=St Helier, S=Jersey, PostalCode=JE4 9NU, C=JE

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
46241CDE5C7B500B51C5F1328228F2A9

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:V/SrQOz/c/wtCtX9BaFAC8rJBLSs5oXQgaDmOdzd/s3g:VAQc+Bah8r7LSCoXlSVag

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 3F, 42, 00, E8, 09, 2C, 00, 00, A3, A4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 36, 42, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Entropy:
7.9710

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file pandotoolbar.exe has been seen being distributed by the following URL.

Remove pandotoolbar.exe - Powered by Reason Core Security