mytmpinstaller.exe

Click Yes

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application mytmpinstaller.exe by Click Yes has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. It is also typically executed from the user's temporary directory.
Publisher:
Click Yes  (signed and verified)

MD5:
9d1f76a2cc75fc6f2721ac1d7d07f863

SHA-1:
b5c07405b267f9e7e89450413793eedb88d3136d

SHA-256:
98e17a0d90c515168fb02f14c5e409c9fc12c26d4c9a509d9d2deff6fc84de38

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
5/8/2024 4:18:35 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.Outbrowse.AV
581

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
PUA/Outbrowse.Gen
3.6.1.96

avast!
OutBrowse-AE [PUP]
2014.9-150329

AVG
Downloader
2016.0.3156

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
infected with Trojan.OutBrowse.225
9.0.1.088

Emsisoft Anti-Malware
Dropped:Application.Bundler.Outbrowse.AV
8.15.07.03.04

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/29/2015

G Data
NSIS.Application.OutBrowse.AC
15.3.25

herdProtect (fuzzy)
2015.7.3.16

K7 AntiVirus
Unwanted-Program
13.202.15417

Malwarebytes
PUP.Optional.Outbrowse.Gen
v2015.07.03.04

McAfee
Adware-OutBrowse.e
5600.6812

MicroWorld eScan
Dropped:Application.Bundler.Outbrowse.AV
16.0.0.552

NANO AntiVirus
Trojan.Win32.OutBrowse.dpqifl
0.30.8.659

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.29.9

Sophos
OutBrowse Revenyou
4.98

VIPRE Antivirus
Threat.4784459
38552

File size:
575.7 KB (589,560 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\mytmpinstaller.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/4/2015 3:58:22 AM

Valid to:
10/22/2015 7:00:12 AM

Subject:
CN=Click Yes, O=Click Yes, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121276DF31F86B383F60209F1B136866206

File PE Metadata
Compilation timestamp:
12/5/2009 5:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:dlBF/xWUbrpJuzXDSo3lCPWo5RnRKwP2xHH8QkEszoyTuK:dl1WU7uNlO5pRkx8QEJ

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove mytmpinstaller.exe - Powered by Reason Core Security