setupytd.exe

YTD Video Downloader

GreenTree Applications srl

The application setupytd.exe by GreenTree Applications srl has been detected as a potentially unwanted program by 19 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.ytddownloader.com and multiple other hosts.
Publisher:
GreenTree Applications srl  (signed and verified)

Product:
YTD Video Downloader

Version:
4.8.9

MD5:
06f48096a0be1f052fe5151b782785e3

SHA-1:
1baf66edc587c1767c5b7f9326196cfc58007b82

SHA-256:
f4227f3799dda7259e00ac5f968b5151da9cf3381df13ca993f1f546681ca448

Scanner detections:
19 / 68

Status:
Potentially unwanted

Explanation:
This is part of a Greentree bundled installer, which includes various adware, toolbars and co-bundled potentially unwanted apps pushed to the user upon setup.

Analysis date:
4/25/2024 7:21:49 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Widgi.opqa
7.11.193.202

avast!
Win32:Adware-gen [Adw]
2014.9-150228

AVG
Downloader
2016.0.3184

Bkav FE
W32.Clod5b0.Trojan
1.3.0.4923

Comodo Security
ApplicUnwnt
19363

Dr.Web
Adware.BGuard.24
9.0.1.059

ESET NOD32
Win32/Bundled.Toolbar.Ask.G potentially unsafe (variant)
9.11218

G Data
Win32.Adware.Spigot
15.2.24

IKARUS anti.virus
PUA.BrowserSafeGuard
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13218

Kaspersky
not-a-virus:AdWare.MSIL.RocketTab
14.0.0.2416

Malwarebytes
PUP.Optional.Spigot
v2015.02.28.08

McAfee
Artemis!799D6FC1E979
5600.6840

NANO AntiVirus
Riskware.Win32.Bundled.dacits
0.28.0.60253

Panda Antivirus
Trj/NsisDownloader.A
15.02.28.08

Reason Heuristics
PUP.Optional.Installer
15.2.28.20

Trend Micro House Call
Suspicious_GEN.F47V1115
7.2.59

VIPRE Antivirus
Trojan.Win32.Generic
31110

Zillya! Antivirus
Adware.RocketTab.Win32.32
2.0.0.1908

File size:
10.6 MB (11,124,008 bytes)

Product version:
4.8.9.0.7

Copyright:
Copyright © 2007-2015 GreenTree Applications SRL

Original file name:
Uninstall.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\programs\setupytd.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
2/11/2015 4:41:38 PM

Valid to:
11/18/2015 10:32:14 PM

Subject:
CN=GreenTree Applications srl, O=GreenTree Applications srl, L=Bucuresti, C=RO

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00A6EF103DF56DEA7B

File PE Metadata
Compilation timestamp:
2/25/2012 2:19:59 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
196608:HYIx4Pvv7HuFrs7NfTkZQNniTes4J8dLNkc1Jj8oWnmaoXznQky8/LjCkt:HYlPv7uZs7NLRiCs4lc1JjBW3ELjCkt

Entry address:
0x39E3

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 91, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, C0, 82, 40, 00, 6A, 08, A3, B8, 2E, 47, 00, E8, 37, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, D0, 2D, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 93, 40, 00, FF, 15, 84, 81, 40, 00, 68, 04, 93, 40, 00, 68, C0, AD, 46, 00, E8, 19, 27, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 30, 4C, 00, 57, E8, 07, 27, 00, 00...
 
[+]

Entropy:
7.9993

Packer / compiler:
Nullsoft install system v2.x

Code size:
28 KB (28,672 bytes)

The file setupytd.exe has been seen being distributed by the following 27 URLs.

http://get.ytddownloader.com/kits/.../YTDSetup-1979048554.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1998972335.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1991845872.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1492869496.exe

http://get.ytddownloader.com/kits/.../YTDSetup-923273508.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1548872781.exe

http://get.ytddownloader.com/kits/.../YTDSetup-468608418.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1613620648.exe

http://get.ytddownloader.com/kits/.../YTDSetup-553511504.exe

http://get.ytddownloader.com/kits/.../YTDSetup-57409318.exe

http://get.ytddownloader.com/kits/.../YTDSetup-49414871.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1216082486.exe

http://get.ytddownloader.com/kits/.../YTDSetup-1469147965.exe

Remove setupytd.exe - Powered by Reason Core Security