0zq2nkdq.ok1

click trust opT

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file 0zq2nkdq.ok1 by click trust opT has been detected as adware by 28 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. It is also typically executed from the user's temporary directory.
Publisher:
click trust opT  (signed and verified)

MD5:
ed223a9bb31f64d404ddfd1777786a0c

SHA-1:
4a996b191a8201fa0f03772227909f4011d4ab4f

SHA-256:
0f854bdeb3136a4c2615108964432228fc634868ba3e3bba2733b3c346ec04da

Scanner detections:
28 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/10/2024 12:11:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.7
5575765

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Outbrowse.Gen
8.3.1.6

avast!
OutBrowse-IJ [PUP]
150525-2

AVG
Adware Generic_s.EO
2014.0.4311

Bitdefender
Application.Bundler.Outbrowse.BA
1.0.20.740

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.OutBrowse.161
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BA
10.0.0.5366

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
5/28/2015

F-Prot
W32/OutBrowse.J (exact, not disinfectable)
4.6.5.141

F-Secure
Gen:Variant.Application.Bundler
11.2015-28-05_5

G Data
Application.Bundler.Outbrowse.BA
15.5.25

IKARUS anti.virus
not-a-virus:AdWare.OutBrowse
t3scan.1.9.2.0

K7 AntiVirus
Riskware
13.204.16062

Kaspersky
not-a-virus:AdWare.Win32.OutBrowse
15.0.0.543

Malwarebytes
PUP.Optional.OutBrowse
v2015.05.28.05

McAfee
Program.Adware-OutBrowse.e
18.0.204.0

MicroWorld eScan
Application.Bundler.Outbrowse.BA
16.0.0.444

NANO AntiVirus
Trojan.Win32.Generic.dorbni
0.30.24.1636

Quick Heal
Adware.NSIS.OutBrowse.A
5.15.14.00

Reason Heuristics
PUP.Outbrowse.Bundler
15.5.28.17

Sophos
Generic PUA PK
4.98

Trend Micro House Call
TROJ_GE.F848E726
7.2.148

Trend Micro
TROJ_GE.F848E726
10.465.28

Vba32 AntiVirus
Adware.Outbrowse
3.12.26.4

VIPRE Antivirus
Threat.5085447
40552

File size:
625.3 KB (640,344 bytes)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\0zq2nkdq.ok1

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
3/16/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=click trust opT, O=click trust opT, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
2DED1B7D5C81898CA25652B6EF8A0EE1

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:qNt6G/glY4+LSaYrwmOHEWXJQaHLzWucKpb4E5Nmz0Wd:qNtslY4+LY3Odj5FAgu

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove 0zq2nkdq.ok1 - Powered by Reason Core Security