installer_1freeantispyware_dutch.exe

Just Accept

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application installer_1freeantispyware_dutch.exe by Just Accept has been detected as adware by 9 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Just Accept  (signed and verified)

MD5:
57cd0883ba13fe8f9eecad42479cc794

SHA-1:
321f4a2cdc48b8344e7be48887d889f2727c9843

SHA-256:
60177f567a6acec3755eea62fa8f1aec5fea8686dd24e10e5f56552442509e8e

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
5/2/2024 5:52:05 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
APPL/Downloader.Gen
7.11.198.162

AVG
Generic
2015.0.3245

Dr.Web
Trojan.OutBrowse.54
9.0.1.05190

F-Secure
Riskware.Gen:Variant.Application.Bundler
5.13.68

IKARUS anti.virus
Trojan-Clicker.Win32.Agent
t3scan.1.8.5.0

K7 AntiVirus
Unwanted-Program
13.188.14484

Malwarebytes
PUP.Optional.OutBrowse
v2014.12.29.01

Reason Heuristics
PUP.JustAccept.a
14.12.29.12

VIPRE Antivirus
Threat.4150696
35418

File size:
574.4 KB (588,216 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_1freeantispyware_dutch.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
11/11/2014 10:11:12 AM

Valid to:
11/12/2015 10:11:12 AM

Subject:
CN=Just Accept, O=Just Accept, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112140B0F5C56686295F63DE0A97ABB5EC76

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:nqPG39eum1oIcRLN9DQB7KxYMEqJ8FWqAmfsDDCBuF/2M:ncGNeD6IcRLN2AzEq7qAmfuDCBuF/2

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove installer_1freeantispyware_dutch.exe - Powered by Reason Core Security