bvddsetup.exe

Best Video Downloader

Alactro LLC

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application bvddsetup.exe by Alactro has been detected as adware by 8 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Alactro LLC  (signed and verified)

Product:
Best Video Downloader

Description:
Installer

Version:
2012.4.25.958

MD5:
fd738f1dd41180ce7e0ad7b64f2d4037

SHA-1:
25886098009c079a24afc4165d07d78aa026ae97

SHA-256:
fb194b37f3dba2d41c4b7ff992fde3492db69e8ad9b5cb5f8d68f14fbe962cd9

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
4/24/2024 6:54:55 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Yontoo.Gen2
7.11.96.250

Comodo Security
Heur.Suspicious
16777

Dr.Web
Adware.Plugin.8
9.0.1.0269

ESET NOD32
Win32/Adware.Yontoo
8.8696

McAfee
Artemis!FD738F1DD411
5600.6995

Reason Heuristics
PUP.Installer.Alactro.J
14.9.26.19

Trend Micro House Call
TROJ_GEN.RC1H1ET
7.2.269

VIPRE Antivirus
Yontoo
20570

File size:
1.3 MB (1,342,024 bytes)

Product version:
1.11.00

Copyright:
Copyright (c) 2012 Alactro LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\bvddsetup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
5/26/2011 4:13:23 PM

Valid to:
5/26/2012 4:13:23 PM

Subject:
CN=Alactro LLC, O=Alactro LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
27E40C73BA04BA

File PE Metadata
Compilation timestamp:
3/10/2011 8:55:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:fXELkiAnXkqEFBGBf+zCL9IKpijEQhPuBruvbpclhmTDXt:vCkiAOFBGMz29IhNPuBruDpMmvXt

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Entropy:
7.9975

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove bvddsetup.exe - Powered by Reason Core Security