videotomp3setup.exe

Video To MP3

Install Core

The installer utilizes the installCore download manager which may bundle additional offers for various ad-supported toolbars, extensions and utilities. The application videotomp3setup.exe, “Video To MP3 Installer” by Install Core has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the installCore installer. The setup program uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from apps.foxtab.com.
Publisher:
Video To MP3 Tech  (signed by Install Core)

Product:
Video To MP3

Description:
Video To MP3 Installer

Version:
3.1.0.0

MD5:
22d18a6ce31a7479f5bac0180bfde6ce

SHA-1:
fc59c3f56da1f717fb56eeb15f68809692ee1af5

SHA-256:
94ac022e07e3b3473ba0af69a44380358567ad2804104b84ee5fe22585935ebb

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/26/2024 4:11:54 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.InstallCore
7.1.1

Avira AntiVirus
PUA/InstallCore.Gen
8.3.1.6

avast!
Win32:InstallCore-F [PUP]
2014.9-151108

Baidu Antivirus
Adware.Win32.InstallCore
4.0.3.15118

Bkav FE
W32.HfsAdware
1.3.0.7133

Clam AntiVirus
W32.Adware.InstallCore-2
0.98/21511

Comodo Security
ApplicUnwnt.Win32.AdWare.InstallCore.0
23070

Dr.Web
Trojan.InstallCore.941
9.0.1.0312

ESET NOD32
Win32/InstallCore.D potentially unwanted (variant)
9.12138

Fortinet FortiGate
Riskware/InstallCore
11/8/2015

F-Prot
W32/Agent.MC.gen
v6.4.7.1.166

G Data
Win32.Adware.InstallCore.DX
15.11.25

Malwarebytes
Adware.Agent
v2015.11.08.05

McAfee
Artemis!22D18A6CE31A
5600.6587

NANO AntiVirus
Trojan.Win32.Agent.bxnsxq
0.30.24.3079

Reason Heuristics
PUP.installCore.VideoToMP3Tech.Installer (M)
15.11.8.17

Sophos
Install Core Installer (PUA)
4.98

Vba32 AntiVirus
SScope.Malware-Cryptor.InstallCore.530A
3.12.26.4

VIPRE Antivirus
InstallCore
43136

File size:
477.5 KB (488,968 bytes)

Product version:
3.1.0.0

Copyright:
Copyright © InstallCore

File type:
Executable application (Win32 EXE)

Bundler/Installer:
installCore

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\videotomp3setup.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/1/2011 7:00:00 PM

Valid to:
2/2/2012 6:59:59 PM

Subject:
CN=Install Core, O=Install Core, STREET=Nisim Aloni 21, L=Tel Aviv, S=Tel Aviv, PostalCode=62919, C=IL

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
2BCA6BFDAB7E5637BA8E7E9C6400CC75

File PE Metadata
Compilation timestamp:
6/19/1992 6:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:BgNiDpiSAJn2tnMhlBu2N1daoizI3EMMLqW8:BM+q2u7tgI3EMMLqW8

Entry address:
0x508510

Entry point:
60, BE, 00, 00, 8A, 00, 8D, BE, 00, 10, B6, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Entropy:
7.8588

Packer / compiler:
UPX 2.90LZMA

Code size:
420 KB (430,080 bytes)

The file videotomp3setup.exe has been seen being distributed by the following URL.

Remove videotomp3setup.exe - Powered by Reason Core Security