ccnfd_1_10_0_2.sys

Click Caption Driver x86

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_2.sys by CLICKCAPTION has been detected as adware by 5 anti-malware scanners. It runs as a Windows kernel mode device driver named “ccnfd_1_10_0_2”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x86

Version:
1.10.0.2

MD5:
d3bd0042985e0cf578691666c6562e9c

SHA-1:
02bb283292f38d872f614a6fd5e8f0aed48c166d

SHA-256:
28427d380ceb492ccbbce59a5c1bf73623a8459eee358c0c1402a130559299c4

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
5/2/2024 11:39:46 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Popad
7.1.1

Dr.Web
Adware.Popad.10
9.0.1.0318

IKARUS anti.virus
AdWare.Vitruvian
t3scan.1.8.3.0

Malwarebytes
PUP.Optional.ClickCaption.A
v2014.11.14.02

Reason Heuristics
PUP.CLICKCAPTION.R
14.11.21.23

File size:
51.5 KB (52,728 bytes)

Product version:
1.10.0.2

Copyright:
Copyright (C) 2014

Original file name:
ccnfd.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_2.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/5/2014 12:18:53 AM

Valid to:
9/5/2016 12:18:53 AM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/22/2012 4:34:53 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:VP47urAd7AVbTXO2vZd1VjXjurCIDaCCepa+ez8oc3fTnuC5Etq2JHV8:147ue7ITew1JXCrdDqe43cPjB+tfK

Entry address:
0xA085

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 8C, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 08, 8B, 01, 00, B8, 00, 8C, 01, 00, C1, E8, 08, 33, 02, A3, 00, 8C, 01, 00, 75, 07, 8B, C1, A3, 00, 8C, 01, 00, F7, D0, A3, 04, 8C, 01, 00, 5D, E9, 51, E7, FF, FF, CC, 2C, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A8, A4, 00, 00, 94, 8A, 00, 00, 18, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, A4, 00, 00, 80, 8A, 00, 00, 24, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, A4, 00, 00, 8C, 8A, 00, 00, 00...
 
[+]

Code size:
34.8 KB (35,584 bytes)

Driver
Display name:
ccnfd_1_10_0_2

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_2.sys - Powered by Reason Core Security