hs0swapk.exe

Free YouTube Downloader

Bonjoy Software

The application hs0swapk.exe, “Free YouTube Downloader Setup Program” by Bonjoy Software has been detected as adware by 7 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The installer uses the OpenCandy monitzation platform which will donwload and install offers in the setup for potentially unwanted software including ad/search-supported toolbars. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from getyoutubedownloader.com.
Publisher:
How, Inc  (signed by Bonjoy Software)

Product:
Free YouTube Downloader

Description:
Free YouTube Downloader Setup Program

Version:
4.0

MD5:
f14f199365ad512020b16bb0b3fd5470

SHA-1:
9fd6b57fa6eca37f18d765d5aca39ee191b1ffaa

SHA-256:
55dff30881981aa970dd42bee98eb46b1bcbafdcdf00ee795295868221ce0f2a

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Packages the OpenCandy software bundler that offers to install additional software and may include web browser add-ons and toolbars which display advertising (based on publisher settings and geo context).

Analysis date:
4/26/2024 9:45:51 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.OpenCandy.161
9.0.1.0197

ESET NOD32
Win32/OpenCandy.A potentially unsafe (variant)
9.11942

K7 AntiVirus
Unwanted-Program
13.206.16567

Kaspersky
not-a-virus:Downloader.Win32.Agent
14.0.0.1727

Panda Antivirus
Generic Suspicious
15.07.16.03

Reason Heuristics
PUP.BonjoySoftware.Installer (M)
15.7.16.15

VIPRE Antivirus
Opencandy
42020

File size:
1.1 MB (1,180,160 bytes)

Product version:
4.0

Copyright:
How Inc.

Original file name:
Free YouTube DownloaderSetup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\hs0swapk.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
12/28/2014 7:00:00 PM

Valid to:
12/29/2015 6:59:59 PM

Subject:
CN=Bonjoy Software, O=Bonjoy Software, STREET="510 Market St #301", L=San Diego, S=CA, PostalCode=92101, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CD3BC6FFAA74061B7CABDCB0D74FBB12

File PE Metadata
Compilation timestamp:
6/30/2015 9:29:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:LAO3pHNRCEl4EDgDTxEVrG067qoGm8OnVK4Q:LH54YATxEstLGQnnQ

Entry address:
0x57424

Entry point:
E8, 75, 98, 00, 00, E9, 79, FE, FF, FF, CC, CC, 68, 00, 70, 45, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, B8, A2, 49, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 6A, 0C, 68, F8, 19, 49, 00, E8, 9B, FF, FF, FF, 6A, 0E, E8, BC, 22, 00, 00, 59, 83, 65, FC, 00, 8B, 75, 08...
 
[+]

Entropy:
7.2868

Code size:
499.5 KB (511,488 bytes)

The file hs0swapk.exe has been seen being distributed by the following URL.

Remove hs0swapk.exe - Powered by Reason Core Security