video download toolbar.exe

IronInstall

The application video download toolbar.exe by IronInstall has been detected as adware by 7 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from 50ftwares.com.
Publisher:
IronInstall  (signed and verified)

MD5:
8ddacd11731356c6f6ae812d8fdcf4d1

SHA-1:
071e9c3607661d88ef35f61de06b968bb3ca1f93

SHA-256:
e034e8ef6e32f0bfc2e70a5e5afb1936147b472ee372cfb6f087c0ee0887d78e

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/27/2024 6:14:21 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Installer-I [PUP]
150717-0

Dr.Web
Adware.InstallCore.101
9.0.1.05190

ESET NOD32
Win32/InstallCore.BH potentially unwanted application
7.0.302.0

F-Prot
W32/Backdoor2.HRPX
4.6.5.141

Reason Heuristics
PUP.installCore.IronInst (M)
16.4.14.17

Sophos
PUA 'Install Core Click run software'
5.23

VIPRE Antivirus
Threat.4150696
48236

File size:
598.2 KB (612,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\video download toolbar.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/20/2012 12:00:00 AM

Valid to:
11/20/2015 11:59:59 PM

Subject:
CN=IronInstall, O=IronInstall, STREET=63 Rothschild Blvd., L=Tel-Aviv, S=NA, PostalCode=65785, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2DC5BB8E9D823CD0C4F09AE859BBBEAC

File PE Metadata
Compilation timestamp:
6/20/1992 3:52:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:8rslasGBnvvXy1OXPSiVFJuYii7K09Z+xOFETLyk7xHn5t:8AUPBnvvXDXP3VFJxKiZ+xNLvT

Entry address:
0x12EF80

Entry point:
60, BE, 00, 40, 4A, 00, 8D, BE, 00, D0, F5, FF, C7, 87, 10, 47, 0E, 00, 4B, 3F, D8, 6B, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46...
 
[+]

Entropy:
7.8465

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
560 KB (573,440 bytes)

The file video download toolbar.exe has been seen being distributed by the following URL.

Remove video download toolbar.exe - Powered by Reason Core Security