Mp3Rocketsvc.exe

Mp3Rocket Toolbar Helper Service

CreativeToolbarSolutions.com

The application Mp3Rocketsvc.exe by CreativeToolbarSolutions.com has been detected as a potentially unwanted program by 5 anti-malware scanners. It runs as a windows Service named “Mp3Rocket Toolbar Helper”. While running, it connects to the Internet address i0-h0-s1033.p0-mia.cdngp.net on port 80 using the HTTP protocol.
Publisher:
Mp3Rocket  (signed by CreativeToolbarSolutions.com)

Product:
Mp3Rocket Toolbar Helper Service

Version:
2, 1, 0, 0

MD5:
136be74fcd94ca9c3c29a74db71d3c3e

SHA-1:
84b2665ac4a29cb7dfa90628b37528bac80c8114

SHA-256:
a0ba9d3e56b11d9d888ba6f07c289a49ffac6a36f3aee44a6bc0fe3c3fe18942

Scanner detections:
5 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 1:13:47 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Zwangi-CV [PUP]
2014.9-140420

AVG
OneStepSearcher.V
2015.0.3498

Fortinet FortiGate
Adware/OneStep
4/20/2014

McAfee
Adware-OneStep.l
5600.7154

Reason Heuristics
PUP.Service.CreativeToolbarSolutions.M
14.11.21.23

File size:
246.8 KB (252,704 bytes)

Product version:
2, 1, 0, 0

Copyright:
Copyright (C) 2010-2011

Original file name:
Mp3Rocketsvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mp3 rocket toolbar\mp3rocketsvc.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
8/17/2010 7:00:00 PM

Valid to:
8/17/2012 6:59:59 PM

Subject:
CN=CreativeToolbarSolutions.com, O=CreativeToolbarSolutions.com, STREET=2141 Rosecrans Ave, STREET=Suite 2020, L=El Segundo, S=CA, PostalCode=90245, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00FD975AB81E7B99A2FF1DDA17C05DB26E

File PE Metadata
Compilation timestamp:
12/8/2010 4:00:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:A2uarcQ9FENviVPws7qyUXWvnYFWMZfy73w28hL:A2uaIQ9F2KtwsDUmvn6RkCL

Entry address:
0x1C23D

Entry point:
E8, E4, 7F, 00, 00, E9, A4, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, A0, B3, 43, 00, 00, 74, 05, E9, 97, 80, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01, 83, EA, 01...
 
[+]

Entropy:
6.5502

Code size:
175 KB (179,200 bytes)

Service
Display name:
Mp3Rocket Toolbar Helper

Description:
Updates Toolbar component to ensure that you always have the latest features.

Type:
Win32OwnProcess, InteractiveProcess


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i0-h0-s1017.p6-ord.cdngp.net  (174.35.56.86:80)

TCP (HTTP):
Connects to i0-h0-s1033.p0-mia.cdngp.net  (174.35.36.41:80)

Remove Mp3Rocketsvc.exe - Powered by Reason Core Security