TubeBoxSetup.exe

TubeBox

Freemium GmbH

The application TubeBoxSetup.exe by Freemium GmbH has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Covus installer. This is the uninstaller utility registered in the Windows Control Panel for the program TubeBox by Freetec. This file is typically installed with the program TubeBox by Freetec Ltd..
Publisher:
Freetec  (signed by Freemium GmbH)

Product:
TubeBox

Version:
1.0.0.0

MD5:
d399de14e18b0d54f6e29da11b3590cf

SHA-1:
12a4cdca1b9ff79f9afb89a0b6cd2b74bfa5286e

SHA-256:
6fad3db63b0f623fa304634808b45ac3937291ac03efa9707616f1880ac9cfa2

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/26/2024 5:39:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Covus.Freemium.Bundler (M)
16.7.7.16

File size:
419.5 KB (429,536 bytes)

Product version:
1.0.0.0

Copyright:
Copyright (c) Freetec. All rights reserved.

Original file name:
TubeBoxSetup.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Covus

Language:
English (United States)

Common path:
C:\ProgramData\package cache\{556e97d3-dfe2-4841-b3e5-169f7ee83716}\tubeboxsetup.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/13/2012 10:34:07 AM

Valid to:
2/13/2013 10:34:07 AM

Subject:
CN=Freemium GmbH, O=Freemium GmbH, L=Berlin, S=Berlin, C=DE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121252CF10F5361359FEF99CB5B54F17E94

File PE Metadata
Compilation timestamp:
9/3/2012 3:44:40 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:cLObe2mmLVKEtIipM/VpyFcehHmCoj86wEUxBsfnc2X30fNfARpXL5VRLr7Qh:cKbe2meV3IipMkHmCoj86wTBsL2AN/I

Entry address:
0x474B

Entry point:
E8, AC, 14, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2A, 83, 78, 10, 03, 75, 24, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 05, E8, 01, 15, 00, 00, 33, C0, 5D, C2, 04, 00, 68, 55, 47, 40, 00, FF, 15, 7C, 11, 40, 00, 33, C0, C3, 8B, FF, 55, 8B, EC, 57, BF, E8, 03, 00, 00, 57, FF, 15, 84, 11, 40, 00, FF, 75, 08, FF, 15, 80, 11, 40, 00, 81, C7, E8, 03, 00, 00, 81, FF, 60, EA, 00...
 
[+]

Code size:
311.5 KB (318,976 bytes)

Program Uninstaller
Program name:
TubeBox

Display publisher:
Freetec

Display version:
1.0.0.0

Uninstall string:
"C:\ProgramData\Package Cache\{556e97d3-dfe2-4841-b3e5-169f7ee83716}\TubeBoxSetup.exe" /uninstall


The file TubeBoxSetup.exe has been discovered within the following program.

TubeBox  by Freetec Ltd.
Publisher's description - “The TubeBox facilitates video search many suppliers directly from the program. And finding your favorite videos is easier than on the video page itself, because you do not even need to restart the browser.”
tubebox.org
36% remove it
 
Powered by Should I Remove It?

Remove TubeBoxSetup.exe - Powered by Reason Core Security