iwantthis.exe

I Want This

Amazing Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application iwantthis.exe, “I Want This Installer” by Amazing Apps has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps  (signed by Amazing Apps)

Product:
I Want This

Description:
I Want This Installer

Version:
1.18.149.149

MD5:
5eeefa9a6dc6854c590ced63612e0a7f

SHA-1:
39a22ec1f076161d2bb7e45a0b531c59e6da02d7

SHA-256:
9e516acc8a638e6dda2c9a0607fb4c0a6e64164f1919ed4895f6f0b55f4d469c

Scanner detections:
31 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
2/7/2026 7:32:56 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Kazy.374109
351

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

AhnLab V3 Security
ASD.Prevention
2013.08.20

Avira AntiVirus
ADWARE/CrossRider.Gen2
7.11.166.228

Baidu Antivirus
Trojan.Win32.Toolbar
4.0.3.16218

Bitdefender
Gen:Variant.Adware.Kazy.374109
1.0.20.245

Bkav FE
HW32.CDB
1.3.0.4959

Comodo Security
ApplicUnwnt
17071

Dr.Web
Adware.GamePlayLabs.31
9.0.1.049

Emsisoft Anti-Malware
Gen:Variant.Adware.Kazy.374109
8.16.02.18.07

ESET NOD32
Win32/Toolbar.CrossRider (variant)
10.10247

Fortinet FortiGate
Adware/CrossRider
2/18/2016

F-Prot
W32/VidSav.A.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Kazy.374109
11.2016-18-02_5

G Data
Gen:Variant.Adware.Kazy.374109
16.2.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.183.13029

Malwarebytes
PUP.Optional.IWantThis.A
v2016.02.18.07

McAfee
Artemis!1C50AC2FAC62
5600.6485

MicroWorld eScan
Gen:Variant.Adware.Kazy.374109
17.0.0.147

NANO AntiVirus
Riskware.Win32.Agent.dagpbi
0.28.2.61861

Quick Heal
Adware.Crossid.r5 (Not a Virus)
2.16.14.00

Reason Heuristics
PUP.50OnRed.AmazingApps.Installer (M)
16.2.18.19

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.16216

Sophos
AppRider
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
9315

Trend Micro House Call
TROJ_SPNR.0BHI12
7.2.49

Trend Micro
TROJ_SPNR.0BHI12
10.465.18

VIPRE Antivirus
GamePlayLabs
32176

XVirus List
Win32.Detected
2.8.7

Zillya! Antivirus
Backdoor.PePatch.Win32.38974
2.0.0.1906

File size:
1.8 MB (1,868,952 bytes)

Copyright:
Copyright 215 Apps

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\installer_for_vafplayer_003159\iwantthis.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
4/30/2012 6:00:00 PM

Valid to:
5/1/2013 5:59:59 PM

Subject:
CN=Amazing Apps, O=Amazing Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2E307885017928B61D4F2CEF5EB10A05

File PE Metadata
Compilation timestamp:
1/5/2010 5:09:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
49152:ZQtNlwCyAK3zvDCyBXa0JQlMv2X6KwRjUjD3+Nuz:yJwbpvBBXafuW6KwvNuz

Entry address:
0x4044

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 97, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 43, 4F, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, A6, 52, 00, 00, A3, 88, 5C, 42, 00, 53, C7, 04, 24, 08, 00, 00, 00, E8, 26, 32, 00, 00, A3, 38, 5D, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, D0, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 68, 5D...
 
[+]

Entropy:
7.9926  (probably packed)

Code size:
33 KB (33,792 bytes)

Remove iwantthis.exe - Powered by Reason Core Security