awh1ef8.tmp

Click Yes

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file awh1ef8.tmp by Click Yes has been detected as adware by 6 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
Click Yes  (signed and verified)

MD5:
5d1c171805cb038598b1a0ebd878a980

SHA-1:
96937ee033e954ad04e42a416eb2d0688fd55e77

SHA-256:
9717404242b43929d187ba600384c9c7e817bd1904a5ccd67372e9d1ef7e84fd

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 10:26:04 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.180.154

avast!
Malware-gen
141023-1

Dr.Web
infected with Trojan.Packed.29192
9.0.1.05190

ESET NOD32
Win32/OutBrowse.AY
8.10604

McAfee
Adware-OutBrowse.b
5600.6969

Reason Heuristics
PUP.ClickYes.K
14.11.3.21

File size:
553.6 KB (566,880 bytes)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Local settings\temp\awh1ef8.tmp

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/21/2014 1:00:12 PM

Valid to:
10/22/2015 1:00:12 PM

Subject:
CN=Click Yes, O=Click Yes, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112179D435052EEAF0AF4A60C93CF0595346

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:s9zFkMpnkIjf6phabPV9iyRzBGZ2eQFAuALB3Z4dwktD:s9zFkMpnkISY50yU2eQFAbtZ4dwa

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove awh1ef8.tmp - Powered by Reason Core Security