ccnfd_1_10_0_2.sys

Click Caption Driver x64

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_2.sys by CLICKCAPTION has been detected as adware by 3 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “ccnfd_1_10_0_2”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x64

Version:
1.10.0.2

MD5:
0cb2af672cb62a1d196bdf30999c4559

SHA-1:
194ebd53b76c95fdac169342a438ffb7a8f2f51e

SHA-256:
fe31e6910ae239cbb5c5ef213ea2825f7a2a80176e1a7097802acdd6e68c6251

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
5/2/2024 2:23:05 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Plugin.274
9.0.1.0316

Malwarebytes
PUP.Optional.ClickCaption.A
v2014.11.12.10

Reason Heuristics
PUP.CLICKCAPTION.R
14.11.21.23

File size:
56.9 KB (58,232 bytes)

Product version:
1.10.0.2

Copyright:
Copyright (C) 2014

Original file name:
ccnfd.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_2.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 8:18:53 PM

Valid to:
9/4/2016 8:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/22/2012 12:34:56 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:KiBIL6sCyo5oIUo0I77nPaXq4Fs+hMeGlDOtcRn3bNl:PC6sCysD7L+Fs+hYOtcRn3bNl

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Code size:
44 KB (45,056 bytes)

Driver
Display name:
ccnfd_1_10_0_2

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_2.sys - Powered by Reason Core Security