pbqrmvbub

Search Protect

ClientConnect LTD

The file belongs to the ClientConnect (Conduit/Perion) platform, a utility that bundles and monetizes search toolbars and browser add-ons. The file pbqrmvbub by ClientConnect has been detected as adware by 16 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from sp-storage.spccint.com. While running, it connects to the Internet address cms.dmccint.com on port 80 using the HTTP protocol.
Publisher:
Client Connect LTD  (signed by ClientConnect LTD)

Product:
Search Protect

Version:
2.20.30.80

MD5:
6766ed6d645388b53c25ae90028f3a14

SHA-1:
f6fc200d28084e048f2286797a9eb9530d651f80

SHA-256:
11e6d227cf3ab9206c1f8b5844ef246ee7601c9f072debd01be91c3a6229490e

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
4/26/2024 3:21:27 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.SearchProtect.2
722

avast!
Win32:Conduit-B [PUP]
2014.9-150213

AVG
Generic
2016.0.3200

Baidu Antivirus
Adware.Win32.Conduit
4.0.3.15213

Dr.Web
Adware.Conduit.45
9.0.1.044

ESET NOD32
Win32/ClientConnect.A potentially unwanted (variant)
9.11169

F-Secure
Gen:Variant.Application.SearchProtect
11.2015-13-02_6

G Data
Win32.Application.SearchProtect.AA@gen
15.2.25

Malwarebytes
PUP.Optional.SearchProtect.A
v2015.02.13.05

McAfee
Artemis!6B6D7AA9ADE0
5600.6856

MicroWorld eScan
Gen:Variant.Application.SearchProtect.2
16.0.0.132

Qihoo 360 Security
Win32/Application.433
1.0.0.1015

Reason Heuristics
PUP.Conduit
15.2.13.6

Sophos
Conduit Search Protect
4.98

Trend Micro House Call
Suspici.44A95FC4
7.2.44

VIPRE Antivirus
Conduit
37508

File size:
9 MB (9,430,560 bytes)

Product version:
2.20.30.80

Copyright:
© 2014 ClientConnect Ltd.

Original file name:
SearchProtect

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\avaxvbxvgx\pbqrmvbub

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
12/30/2014 6:00:00 PM

Valid to:
12/26/2016 5:59:59 PM

Subject:
CN=ClientConnect LTD, OU=Safe Search, O=ClientConnect LTD, L=Ness Ziona, S=Israel, C=IL

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
354F4C7E49A131A6E4BF89B253C78A2D

File PE Metadata
Compilation timestamp:
7/6/2011 9:31:20 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
196608:TS07jHHpkGxWR30j59XOJjDOUdcJ20rZVv9pz60ZqS9prFo:TS0fHpkgWR30vGDpT0956N

Entry address:
0x354B

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, D8, 84, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 80, 40, 00, 68, 01, 80, 00, 00, FF, 15, B8, 80, 40, 00, 55, FF, 15, B0, 82, 40, 00, 6A, 08, A3, 98, 06, 47, 00, E8, 67, 27, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, 05, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 1C, 86, 40, 00, FF, 15, 80, 81, 40, 00, 68, 04, 86, 40, 00, 68, A0, 85, 46, 00, E8, 35, 26, 00, 00, FF, 15, B4, 80, 40, 00, 50, BF, A0, 10, 4C, 00, 57, E8, 23, 26, 00, 00...
 
[+]

Entropy:
7.9959

Packer / compiler:
Nullsoft install system v2.x

Code size:
25 KB (25,600 bytes)

The file pbqrmvbub has been seen being distributed by the following URL.

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to cms.dmccint.com  (23.67.242.80:80)

 
http://cms.dmccint.com/DynamicOffer/17598505/17619628/?mainofferId=17595071&CurrentStep=2&TotalSteps=4&DownloadBrowser=IE&CType=-1&UserMode=-1&DMVersion=1.3.7.76.17618494.01&Language=US-EN

Remove pbqrmvbub - Powered by Reason Core Security