toolbarupdate.exe

VkSmile

The application toolbarupdate.exe has been detected as a potentially unwanted program by 5 anti-malware scanners. The program is a setup application that uses the Nullsoft Install System installer, however the file is not signed with an authenticode signature from a trusted source.
Publisher:
VkSmile

Product:
VkSmile

Version:
1.5.5

MD5:
72dd1e28e6742e2868dd1d4044d465ce

SHA-1:
85596acff74da41ab4ca6152dc9fe37361ca8dda

SHA-256:
0dca6a38c07af1b72b9bf11e13ae15e51814907614434f05530f4199bf84d646

Scanner detections:
5 / 68

Status:
Potentially unwanted

Explanation:
This is part of the Crossrider Internet browser extension framework which may modify the user's web browser settings including changing the home and search pages.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
5/6/2024 9:48:08 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.VkSmile
188838

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/Toolbar.Neobar.B potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:AdWare.JS.Agent
15.0.0.562

Reason Heuristics
Threat.Win.Reputation.IMP
16.12.10.3

File size:
1.3 MB (1,325,446 bytes)

Product version:
1.5.5

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Install System

Common path:
C:\windows\temp\abhtml002\toolbarupdate.exe

File PE Metadata
Compilation timestamp:
12/8/2011 5:34:40 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.56

CTPH (ssdeep):
24576:0fMXp0o26TFOTsI1RCx29MfJPYapy9rsKBZ6xHQkwiBqTJwR+yUQ:gwD26Tk/1T9aBYWyZR4Q/4qZyz

Entry address:
0x4040

Entry point:
55, 89, E5, 57, 56, 53, 81, EC, AC, 01, 00, 00, E8, B3, 52, 00, 00, C7, 04, 24, 01, 80, 00, 00, E8, 5F, 4F, 00, 00, 56, C7, 04, 24, 00, 00, 00, 00, E8, C2, 52, 00, 00, 53, A3, 50, 5B, 42, 00, C7, 04, 24, 08, 00, 00, 00, E8, 3E, 32, 00, 00, A3, 00, 5C, 42, 00, 8D, 85, 84, FE, FF, FF, 51, C7, 44, 24, 10, 00, 00, 00, 00, C7, 44, 24, 0C, 60, 01, 00, 00, 89, 44, 24, 08, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, A4, B2, 40, 00, E8, EC, 51, 00, 00, 83, EC, 14, C7, 44, 24, 04, A5, B2, 40, 00, C7, 04, 24, 30, 5C...
 
[+]

Code size:
33 KB (33,792 bytes)

Remove toolbarupdate.exe - Powered by Reason Core Security