ct2383985.xpi

OurWorld.com

The file ct2383985.xpi has been detected as a potentially unwanted program by 10 anti-malware scanners. It loads in Mozilla Firefox as a compliled extension named 'OurWorld.com' created by ClientConnect Ltd..
Remove ct2383985.xpi - Powered by Reason Core Security
MD5:
9d02ac8c1b27358bf7a77f10938ea996

SHA-1:
834a3a8f07233a3be0f1934316006e7f941f84af

SHA-256:
ce50a1dfbb31d9e01ddedc519b97ed7c3a4a63a8d01257b1ccdc550cdb43f7e8

Scanner detections:
10 / 68

Status:
Potentially unwanted

Explanation:
Part of the Conduit/ClientConnect toolbar/extension distribution.

Analysis date:
12/3/2016 1:34:56 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Riskware.SearchProtect
7.1.1

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.14610

Dr.Web
Threat.Undefined
9.0.1.05190

ESET NOD32
Win32/Conduit.SearchProtect.N potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/Conduit_SearchProtect
6/10/2014

McAfee
Artemis!A5069A5826F3
5600.7103

McAfee Web Gateway
Artemis!B58595401A01
7.7103

Reason Heuristics
Adware.ClientConnect.MozillaPlugin.M
14.8.13.21

Trend Micro House Call
TROJ_GEN.F47V0529
7.2.161

VIPRE Antivirus
Adware.JS.Conduit
30168

Remove ct2383985.xpi - Powered by Reason Core Security
File size:
1.8 MB (1,865,322 bytes)

File type:
Cross-Platform Installer Module (XPI), used by Mozilla bundles

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ct2383985.xpi

Mozilla Extension
Name:
ct2383985.xpi

Display:
OurWorld.com

Id:
ct2383985

Creator:
ClientConnect Ltd.

Description:
“Delivers all our best apps to your browser.”

Home page:
http://www.ourtoolbar.com


<RDF xmlns="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:em="http://www.mozilla.org/2004/em-rdf#">
  <Description about="urn:mozilla:install-manifest">
    <em:id>{80f6f9bf-9fd1-4f41-9ddf-6dd070f4f62f}</em:id>
    <em:name>OurWorld.com </em:name>
    <em:unpack>true</em:unpack>
    <em:version>10.31.2.1</em:version>
    <em:description>Delivers all our best apps to your browser.</em:description>
    <em:creator>ClientConnect Ltd.</em:creator>
    <em:homepageURL>http://www.ourtoolbar.com</em:homepageURL>
    <!--em:aboutURL>chrome://CT2383985/content/about</em:aboutURL-->
    <!--em:optionsURL>chrome://CT2383985/content/options</em:optionsURL-->
    <em:updateURL>https://ffupdate.tbccint.com/SB.ashx?ctid=CT2383985&amp;ver=10.31.2.1&amp;itemId=%ITEM_ID%&amp;itemMaxAppVersion=%ITEM_MAXAPPVERSION%&amp;itemStatus=%ITEM_STATUS%&amp;appId=%APP_ID%&amp;targetAppVersion=%APP_VERSION%&amp;currentAppVersion=%CURRENT_APP_VERSION%&amp;updateType=%UPDATE_TYPE%</em:updateURL>
    <em:file>
      <Description about="urn:mozilla:extension:file:CT2383985.jar">
        <em:package>content/</em:package>
        <em:skin>skin/</em:skin>
      </Description>
    </em:file>
    <em:targetApplication>
      <Description>
        <em:id>{ec8030f7-c20a-464f-9b0e-13a3a9e97384}</em:id>
        <em:minVersion>3.5</em:minVersion>
        <em:maxVersion>99.*</em:maxVersion>
      </Description>
    </em:targetApplication>
    <em:bootstrap>false</em:bootstrap>
  </Description>
</RDF>
Remove ct2383985.xpi - Powered by Reason Core Security