ytdsetup.exe

YTD Video Downloader

Greentree Applications SRL

The application ytdsetup.exe, “YTD Video Downloader stub installer” by Greentree Applications SRL has been detected as a potentially unwanted program by 7 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer.
Publisher:
Greentree Applications SRL  (signed and verified)

Product:
YTD Video Downloader

Description:
YTD Video Downloader stub installer

Version:
4.8.9.6

MD5:
b8ddc88d7119c0348fe7f223396b4612

SHA-1:
13d04815479aeab4ed990be98f4b1083eb63f0f6

SHA-256:
e021e39d0a50e2f4c01ad1cc8b9053da052d0c6c99e9f5c91ff618194eab9a9e

Scanner detections:
7 / 68

Status:
Potentially unwanted

Explanation:
This is part of a Greentree bundled installer, which includes various adware, toolbars and co-bundled potentially unwanted apps pushed to the user upon setup.

Analysis date:
4/18/2024 11:54:58 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Adware.Downware.10494
9.0.1.05190

herdProtect (fuzzy)
2015.7.5.0

Qihoo 360 Security
Malware.QVM20.Gen
1.0.0.1015

Reason Heuristics
PUP.Optional.Installer
15.3.31.3

Trend Micro House Call
TROJ_GEN.R047H05B115
7.2.90

Zillya! Antivirus
Downloader.Genome.Win32.53447
2.0.0.2057

File size:
103.3 KB (105,808 bytes)

Product version:
4.8.9.6

Copyright:
(c) 2014 GreenTree Applications SRL. All rights reserved.

Original file name:
YTDStub.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ytdsetup.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
1/6/2015 4:00:00 AM

Valid to:
2/12/2016 4:00:00 PM

Subject:
CN=Greentree Applications SRL, O=Greentree Applications SRL, L=Bucuresti, S=Bucuresti, C=RO, PostalCode=030964, STREET="Bd Decebal Nr 25-29, Etaj 10 Sectorul 3", SERIALNUMBER=J40 /6350 /2011, OID.1.3.6.1.4.1.311.60.2.1.3=RO, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0661DF7E53B40AA5BC5E58DA4EC37F60

File PE Metadata
Compilation timestamp:
7/15/2013 12:09:44 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:we5VOhs5pCax0ojXJtl68gkW+RoeGd8yNkM/Dk22Z7EimH6kDukr/vWF:we5ghsX8ojXJj7Ozd8yNkaa7Eim8ky

Entry address:
0x324D

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 89, 5C, 24, 20, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 98, 3F, 42, 00, E8, 8B, 2D, 00, 00, A3, E4, 3E, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, A0, F4, 41, 00, FF, 15, 64, 71, 40, 00, 68, E4, 91, 40, 00, 68, E0, 36, 42, 00, E8, 35, 2A, 00, 00, FF, 15, B0, 70, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 23, 2A...
 
[+]

Entropy:
7.1953

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove ytdsetup.exe - Powered by Reason Core Security