toolbar114832.exe

DropDownDeals

Web Deals Interactive LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application toolbar114832.exe by Web Deals Interactive has been detected as adware by 10 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software.
Publisher:
Web Deals Interactive LLC  (signed and verified)

Product:
DropDownDeals

Description:
Installer

Version:
2012.10.23.1815

MD5:
aeb17980b1864eb67beaa7bb6849fdd2

SHA-1:
d63617af9fa8013b6135c4053242f3dc0b071463

SHA-256:
defede09779673a8f975c27da2af6edb45a8bdb54a5a4bbb53ccdd315b010e0e

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 1:59:32 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

AhnLab V3 Security
ASD.Prevention
2013.12.18

Baidu Antivirus
Adware.Win32.Agent
4.0.3.131221

Comodo Security
UnclassifiedMalware
17457

Dr.Web
Adware.Plugin.8
9.0.1.0355

ESET NOD32
Win32/Adware.Yontoo (variant)
7.9183

Reason Heuristics
PUP.Installer.WebDealsInteractive.N
14.3.1.13

Rising Antivirus
PE:Trojan.Win32.Generic.136D92E8!325948136
23.00.65.131219

Trend Micro House Call
TROJ_GEN.RCBH1KQ
7.2.355

VIPRE Antivirus
Yontoo
24462

File size:
1.2 MB (1,210,432 bytes)

Product version:
1.11.00

Copyright:
Copyright (c) 2012 Web Deals Interactive LLC. All rights reserv

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\toolbar114832.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/15/2012 9:41:08 PM

Valid to:
5/15/2013 6:52:46 PM

Subject:
CN=Web Deals Interactive LLC, O=Web Deals Interactive LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B7631E3D31FB1

File PE Metadata
Compilation timestamp:
3/11/2011 3:55:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:xXELkiAfAIAkeTbnXqs3redEgsPyVTV4DNQzcj:5CkiAQkeTbn93wE3PyVp2j

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

Remove toolbar114832.exe - Powered by Reason Core Security