iwantthis.exe

I Want This

215 Apps

This is the installer application for a 50onRed advertising supported software package (displays ads in the browser and may hijack the home and search pages of the web browser). The application iwantthis.exe, “I Want This Installer” by 215 Apps has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps  (signed and verified)

Product:
I Want This

Description:
I Want This Installer

Version:
1.16.149.149

MD5:
56b5bedd896616c034103cca8c0ccf7b

SHA-1:
e7d296fa81b4870077f4170f6442b3e70e7fa640

SHA-256:
d482769561ad7287d21eac70db46e0634407ab8a7cce170e4ac340dd74dd4f6a

Scanner detections:
31 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/19/2024 10:53:06 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Plush.2
705

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

Avira AntiVirus
Adware/Agent.494424.26
7.11.173.16

AVG
SmartShopper.K
2016.0.3183

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.1532

Bitdefender
Gen:Variant.Adware.Plush.2
1.0.20.305

Bkav FE
HW32.Paked
1.3.0.4959

Clam AntiVirus
Trojan.LilyJade-1
0.98/18155

Comodo Security
Heur.Suspicious
12423

Dr.Web
Adware.GamePlayLabs.17
9.0.1.061

Emsisoft Anti-Malware
Gen:Variant.Adware.Plush
8.15.03.02.03

ESET NOD32
Win32/Toolbar.CrossRider (variant)
9.10434

Fortinet FortiGate
W32/Toolbar.CROSSRIDER
3/2/2015

F-Prot
W32/GamePlay.D.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Plush.2
11.2015-02-03_2

G Data
Gen:Variant.Adware.Plush
15.3.24

IKARUS anti.virus
AdWare.SuspectCRC
t3scan.1.7.8.0

K7 AntiVirus
Trojan
13.183.13407

Malwarebytes
PUP.Optional.IWantThis.A
v2015.03.02.03

McAfee
Artemis!B62AC846DB5F
5600.6839

MicroWorld eScan
Gen:Variant.Adware.Plush.2
16.0.0.183

NANO AntiVirus
Trojan.Win32.Generic.deinni
0.28.2.62151

Qihoo 360 Security
Win32/Virus.Adware.7e8
1.0.0.1015

Quick Heal
Adware.Crossid (Not a Virus)
3.15.14.00

Reason Heuristics
PUP.Installer.50OnRed
15.3.2.3

Rising Antivirus
NS:PUF.SilenceInstaller!1.9DDF
23.00.65.15228

Sophos
W32/LilyJade-A
4.77

Trend Micro House Call
TROJ_GEN.R06H1EG
7.2.61

Trend Micro
TROJ_GE.7162B978
10.465.02

Vba32 AntiVirus
TrojanDownloader.LilyJade.a
3.12.16.4

VIPRE Antivirus
GamePlayLabs
11974

File size:
1.8 MB (1,870,904 bytes)

Copyright:
Copyright 215 Apps

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\iwantthis.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/24/2011 5:00:00 PM

Valid to:
10/24/2012 4:59:59 PM

Subject:
CN=215 Apps, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=215 Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4D064A782BC23A29CC9B8499A9F4AFB4

File PE Metadata
Compilation timestamp:
1/5/2010 4:09:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
24576:MTwtwoCRSNnhIBP2tBp3Dfwh5vFNqNU7nMfatCoKypVirMHcDjg5EL+wlK6SFdHh:swtB44hDfC1zeTatCoKyqlD3iQ8Fd6Be

Entry address:
0x4044

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, 97, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 43, 4F, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, A6, 52, 00, 00, A3, 88, 5C, 42, 00, 53, C7, 04, 24, 08, 00, 00, 00, E8, 26, 32, 00, 00, A3, 38, 5D, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, D0, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 68, 5D...
 
[+]

Entropy:
7.9926  (probably packed)

Code size:
33 KB (33,792 bytes)

Remove iwantthis.exe - Powered by Reason Core Security