free ven-chromeinstaller.exe

free ven

freeven

This adware is a web browser extension that will inject advertising in the browser in the form of unwanted banners and text-links which may link to malware sites and install unwanted software. The application free ven-chromeinstaller.exe has been detected as adware by 6 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in. The file utilizes the Crossrider browser extension platform. ChromeInstaller is the component designed to install and manage the extension's Google Chrome integration.
Publisher:
freeven

Product:
free ven

Description:
free ven exe

Version:
1000.1000.1000.1000

MD5:
7c29c166207ce48b77e4e60ff1fd4605

SHA-1:
e815ffbe9ab69e5cf2a252d8228f5021597d13a1

SHA-256:
6c3ce8ff8f1225bf8bd823294227fe67be2a99820f8fa8b0b20b269d812ef91e

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Part of the Crossrider toolbar platform. It will download and install the extension for Gogole Chrome.

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/30/2024 10:06:59 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Lyrics
4.0.3.14320

Malwarebytes
PUP.Optional.AddPusHD.A
v2014.03.20.02

Reason Heuristics
PUP.Crossrider.freeven.Y
14.3.15.11

Trend Micro House Call
TROJ_GEN.F47V0316
7.2.79

VIPRE Antivirus
Crossrider
27754

File size:
2 MB (2,051,584 bytes)

Product version:
1000.1000.1000.1000

Copyright:
Copyright 2011

Original file name:
free ven.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\free ven\free ven-chromeinstaller.exe

File PE Metadata
Compilation timestamp:
3/10/2014 7:04:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
49152:IibYKzvp4B6PAj3osVuBcx4O+4DGR1pSIkfTCUzn+nPRx:IisK14B6PAj3osVZyOx

Entry address:
0xFFE74

Entry point:
E8, 50, 09, 01, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 85, F6, 78, 09, E8, 83, 0A, 01, 00, 3B, 30, 7C, 07, E8, 7A, 0A, 01, 00, 8B, 30, E8, 6D, 0A, 01, 00, 8B, 04, B0, 5E, 5D, C3, 55, 8B, EC, 56, E8, A7, 5D, 00, 00, 8B, F0, 85, F6, 75, 07, B8, 30, 30, 56, 00, EB, 26, 53, 57, 33, FF, BB, 86, 00, 00, 00, 39, 7E, 24, 75, 1B, 6A, 01, 53, E8, FA, 30, 00, 00, 59, 59, 89, 46, 24, 85, C0, 75, 0A, B8, 30, 30, 56, 00, 5F, 5B, 5E, 5D, C3, FF, 75, 08, 8B, 76, 24, E8, 90, FF, FF, FF, 50, 53, 56, E8, 73, EC...
 
[+]

Entropy:
6.8531

Code size:
1.1 MB (1,199,616 bytes)

Scheduled Task
Task name:
free ven-chromeinstaller

Trigger:
Logon (Runs on logon)

Action:
free ven-chromeinstaller.exe \rawdata=nq1hj3qc3rt8kr5mjc8lslyfnifgrhk5tug+nwsx3


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.srvstatsdata.com  (69.16.175.42:80)

 
http://update.srvstatsdata.com/installer_updates/000357/update.json

TCP (HTTP):
Connects to stats.srvstatsdata.com  (176.32.99.41:80)

TCP (HTTP):
Connects to app-static.crossrider.com  (69.16.175.10:80)

Remove free ven-chromeinstaller.exe - Powered by Reason Core Security