YTDownloader.exe

Goobzo LTD

This is part of the Goobzo YTDownloader a browser extension for downloading videos, however, the file will attempt ot modify the user's browser including resetting the home and seach pages as well as inject various forms of unwanted advertising in the browser. The application YTDownloader.exe by Goobzo has been detected as adware by 6 anti-malware scanners. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘YTDownloader’. This file is typically installed with the program YTDownloader by Goobzo Ltd. which is a potentially unwanted software program.
Publisher:
YTDownloader  (signed by Goobzo LTD)

Product:
YTDownloader

Version:
1.0.3.3

MD5:
270bed0eb721d9fc306a6a96e5d7810e

SHA-1:
f34199c403c0d5a4f600624ea4082769a1171d80

SHA-256:
a33786152c0fc9748418c291c687d6196633cca9ba6295f20e44f12f4ba78779

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
8/8/2014 6:42:03 AM UTC  (four months ago)

Scan engine
Detection
Engine version

AVG
MalSign.Skodna
2014.0.3618

McAfee
Artemis!270BED0EB721
5600.7255

McAfee Web Gateway
Artemis!270BED0EB721
7.7255

Reason Heuristics
PUP.Startup.Goobzo.M
14.8.8.2

Trend Micro House Call
TROJ_GEN.F47V1130
7.2.356

VIPRE Antivirus
Goobzo
24196

File size:
2 MB (2,050,408 bytes)

Product version:
1.0.3.3

Copyright:
Copyright (C) 2013

Original file name:
YTDownloader.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ytdownloader\ytdownloader.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/1/2013 9:00:00 PM

Valid to:
5/2/2015 8:59:59 PM

Subject:
CN=Goobzo LTD, O=Goobzo LTD, L=Haifa, S=Israel, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
120B25DDE57B88636AD4D97D23B99C88

File PE Metadata
Compilation timestamp:
11/25/2013 7:19:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Te24hoEjqmD2HOjWlRAsk3ZJblR62wJUSzPXzTeTSf7Nal5kF:Te24ho4tj+3GBs2wPDXzTeTSf7NarkF

Entry address:
0xC68A4

Entry point:
E8, B3, 48, 01, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 56, 8D, 45, 08, 50, 8B, F1, E8, 5B, 16, FF, FF, C7, 06, 5C, CE, 53, 00, 8B, C6, 5E, 5D, C2, 04, 00, C7, 01, 5C, CE, 53, 00, E9, 9F, 16, FF, FF, 8B, FF, 55, 8B, EC, 56, 8B, F1, C7, 06, 5C, CE, 53, 00, E8, 8C, 16, FF, FF, F6, 45, 08, 01, 74, 07, 56, E8, 8F, 1E, FF, FF, 59, 8B, C6, 5E, 5D, C2, 04, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 08, 8B, 47, 04, 85, C0, 74, 47, 8D, 50, 08, 80, 3A, 00, 74, 3F, 8B, 75, 0C, 8B, 4E, 04, 3B, C1, 74, 14, 83, C1, 08...
 
[+]

Code size:
1.1 MB (1,146,880 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
YTDownloader

Command:
"C:\Program Files\ytdownloader\ytdownloader.exe" \boot


The file YTDownloader.exe has been discovered within the following program.

YTDownloader  by Goobzo Ltd.
YTDownloader is a web browser extension that will integrate itself into Chrome, Firefox and Internet Explorer.
www.ytdownloader.com
85% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to lax02s02-in-f5.1e100.net  (74.125.224.197:80)

TCP (HTTP):
Connects to ec2-54-197-238-106.compute-1.amazonaws.com  (54.197.238.106:80)

There are numerous known versions of YTDownloader.exe by YTDownloader.

16 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (ccecf9dc5afff872ee413cb643a858e10dfa03bb)

16 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (6c4a0ec97b742ca3111344a133153a582e209f4f)

16 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (b2eb301209487987fc98eaf3fc21a2e21dd0601d)

16 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (4b386337aa5a91778ad35546a4fab38211e3f28f)

16 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (7600c29d579e5ac91ee65e22da98c1597110bfdc)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (01d254cde538cce6acbfd93b5c57d888fb62b702)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (7e208f712f9e4b29fbe23e5e44f634ead18b4049)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (ec80327a5408b078fc121361b896842afb5adfa9)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (b0c2f3cf47fbc6dae667f6aace1ac211cc777d24)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (ff354767fb050fbbd924f0554b220e892a888f3c)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (ad1b866d2eeac46b8f3be2b20872bf0ed9953303)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (d6ab6aa7bbd50685778c1b41bb3367a3278c3115)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (609c0b2faefdeae9a605e30fa1757cfa3cd368a5)

15 / 68    (Adware)
YTDownloader.exe  1.0.3.9  (b606b298d88377688fa29f3d0671797382bc3588)

10 / 68    (Adware)
YTDownloader.exe  1.0.2.5  (4733150234c5f5f3a11f469c1b79dfc1beefa5d1)

4 / 68      (Adware)
ytd_aff.exe  (8756cd4dedd1254fcbb3d2562efe2c0bd4ce2165)

4 / 68      (Adware)
downloadhelper.exe  (38859b26acddc5e9c646bf79ebbd83500c55ecf5)

1 / 68      (Adware)
SysMenu.dll  (87dd433ac13640ed695a5fda11ee71f450536d17)

3 / 68      (Adware)
ytd.exe  (9537856b12372a71d2c2511d64e738074d8492f6)

5 / 68      (Adware)
sysmenu64.dll  (70b24a19e00f114f9f08a8afbf29f99e083ce379)

Detection Incidence by Country