avs_dvd_copy.exe

OUTBROWSE LTD

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application avs_dvd_copy.exe by OUTBROWSE has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
OUTBROWSE LTD  (signed and verified)

MD5:
8cfc71927fe7e1d725d1999319411acc

SHA-1:
d7572624e7ab3a9f4941e6b1540f64fb5a3073ef

SHA-256:
c8959364effb9461407b4eadf8e1ffb3bdf5fc5b50a6c0d613a12a2e981988fd

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/25/2024 10:27:22 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.170.148

AVG
OutBrowse
2015.0.3363

Dr.Web
Adware.Downware.2081
9.0.1.05190

ESET NOD32
Win32/OutBrowse.AN
8.10355

K7 AntiVirus
Unwanted-Program
13.183.13247

Malwarebytes
PUP.Optional.Downloader
v2014.09.02.04

McAfee
Adware-OutBrowse
5600.7019

NANO AntiVirus
Trojan.Win32.OutBrowse.deioif
0.28.2.61942

Reason Heuristics
PUP.OUTBROWSE.M
14.9.2.15

Sophos
OutBrowse Revenyou
4.98

VIPRE Antivirus
Threat.4784459
32210

File size:
564.8 KB (578,344 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\avs_dvd_copy.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
3/26/2014 9:16:30 AM

Valid to:
3/26/2015 9:16:30 AM

Subject:
CN=OUTBROWSE LTD, O=OUTBROWSE LTD, L=ramat gan, S=Merkaz, C=IL

Issuer:
CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4E9F154E55EEFC

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:RHn31xYLVEhxUBlUMvZtChHfsfG9XsDN8wjI3HozGxfynv5t:R/YRDuMbuwPlax+Rt

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove avs_dvd_copy.exe - Powered by Reason Core Security