ytab_setup.exe

Pavel KRASNOV

This installer (utilizes the InstalleRex from WebPick) is designed to bundle additional software offerings such as adware and malware, mostly web browser extensions in the download manager, with minimal user consent. In most cases the setup process will install a browser extension for IE, Chrome and Firefox by default. The application ytab_setup.exe by Pavel KRASNOV has been detected as adware by 31 anti-malware scanners. The program is a setup application that uses the WebPick InstalleRex installer. It is also typically executed from the user's temporary directory. While running, it connects to the Internet address dl.softservers.net on port 80 using the HTTP protocol.
Publisher:
Pavel KRASNOV  (signed and verified)

MD5:
7877c35bf0e23b8372fdd6a656a7702d

SHA-1:
41b20fa6bc1c8d228023b3f846234dc53bfe8da4

SHA-256:
f31e39dd77c7b380feade8f7515ae5fc0f9ad116f693be3900c940403df43adc

Scanner detections:
31 / 68

Status:
Adware

Explanation:
Bundles additional adware offers in the installer/setup process.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 9:00:32 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Dropper.101
6373653

Agnitum Outpost
PUA.MultiPlug
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
3.6.1.96

avast!
Win32:PUP-gen [PUP]
150319-0

AVG
Adware Generic5.AMTA
2014.0.4311

Bitdefender
Gen:Variant.Adware.Dropper.101
1.0.20.430

Clam AntiVirus
Win.Adware.Dropper-3
0.98/20247

Comodo Security
Application.Win32.Multiplug.GETF
21554

Dr.Web
Trojan.MulDrop5.7854
9.0.1.086

Emsisoft Anti-Malware
Gen:Variant.Adware.Dropper.101
9.0.0.4799

ESET NOD32
Win32/AdWare.MultiPlug.R application
7.0.302.0

Fortinet FortiGate
Riskware/Generic.AC.28568
3/27/2015

F-Prot
W32/S-b3803546
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.Dropper
5.13.68

G Data
Gen:Variant.Adware.Dropper.101
15.3.25

IKARUS anti.virus
Virus.Script
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.202.15399

Kaspersky
not-a-virus:WebToolbar.Win32.Cossder
15.0.0.543

Malwarebytes
PUP.Optional.Installrex
v2015.03.27.06

McAfee
Program.PUP-FEI
16.8.708.2

MicroWorld eScan
Gen:Variant.Adware.Dropper.101
16.0.0.258

NANO AntiVirus
Riskware.Win32.MegaSearch.csvfny
0.30.8.659

Norman
Gen:Variant.Adware.Dropper.101
03.12.2014 13:20:04

nProtect
Trojan/W32.Adond.573688
15.03.27.01

Quick Heal
AdWare.MultiPlug.r5
3.15.14.00

Reason Heuristics
PUP.Bundler.WebPick
15.3.27.6

Rising Antivirus
PE:Malware.Adware!6.1277
23.00.65.15325

Sophos
MultiPlug
4.98

Vba32 AntiVirus
Adware.MegaSearch
3.12.26.3

VIPRE Antivirus
Threat.4150696
38552

Zillya! Antivirus
Trojan.Black.Win32.16669
2.0.0.2118

File size:
560.2 KB (573,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
WebPick InstalleRex

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\addons\ytab_setup.exe

Digital Signature
Signed by:

Authority:
Unizeto Technologies S.A.

Valid from:
1/17/2014 8:46:29 AM

Valid to:
1/17/2015 8:46:29 AM

Subject:
E=pavel0125@hotmail.com, CN="Open Source Developer, Pavel KRASNOV", O=Pavel KRASNOV, C=RU

Issuer:
CN=Certum Level III CA, OU=Certum Certification Authority, O=Unizeto Technologies S.A., C=PL

Serial number:
145B82E22CCF1D1A2268198D76B51075

File PE Metadata
Compilation timestamp:
1/27/2014 11:38:36 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:2lSaGklFSnYZQjGwn5IuHyw6sHXbWSrXL35ihnz9q2rCLh9sr91dz:2pD4YZMGw5/73ZXLanz91+rq1x

Entry address:
0xE3DB

Entry point:
E8, 7E, 44, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C8, ED, 41, 00, E8, DF, 12, 00, 00, E8, CB, 0F, 00, 00, 0F, B7, F0, 6A, 02, E8, 11, 44, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 96, 01, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Code size:
89 KB (91,136 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to i1.stylefun.info  (198.7.61.118:80)

TCP (HTTP):
Connects to dl.softservers.net  (184.154.145.171:80)

TCP (HTTP):
Connects to c1.getapplicationmy.info  (54.201.215.30:80)

Remove ytab_setup.exe - Powered by Reason Core Security