phnbabtbgy.exe

Crime Watch

Great Apps

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application phnbabtbgy.exe by Great Apps has been detected as adware by 13 anti-malware scanners.
Publisher:
Great Apps  (signed and verified)

Product:
Crime Watch

Description:
CrimeWatch

Version:
1.0.0.0

MD5:
97ab6f1c8b615924d51ee4f6d5d874b7

SHA-1:
2ae5991f90be930921437897bdd145ddea388b58

SHA-256:
1cee4f2a62dba5f3b90737250843292e4f09933aa64eb04afc1047ef6348c68b

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 8:49:06 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Adware.Gen7
3.6.1.96

AVG
Generic
2016.0.3129

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.15425

Bkav FE
W32.HfsAdware
1.3.0.6379

Comodo Security
ApplicUnwnt
21884

Dr.Web
Adware.Yontoo.68
9.0.1.05190

ESET NOD32
MSIL/Adware.PullUpdate.N.gen (variant)
9.11530

Kaspersky
not-a-virus:AdWare.MSIL.PullUpdate
15.0.0.543

Malwarebytes
PUP.Optional.CrimeWatch.A
v2015.04.25.03

Panda Antivirus
Generic Suspicious
15.04.25.03

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Injekt.GreatApps
15.4.24.23

Sophos
Generic PUA CK
4.98

File size:
46.5 KB (47,576 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Great Apps 2015

Original file name:
CrimeWatch.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Documents and Settings\{user}\Application data\lacgxjqvbi\dat\phnbabtbgy.exe

Digital Signature
Signed by:

Authority:
Symantec Corporation

Valid from:
2/16/2015 7:00:00 PM

Valid to:
2/17/2016 6:59:59 PM

Subject:
CN=Great Apps, O=Great Apps, L=St. Michael, S=St. Michael, C=BB

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
18DA5D77283E42E4EA6279778229FFBA

File PE Metadata
Compilation timestamp:
4/14/2015 10:42:57 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:CQz9sXMCKZLPhcDjc+fBRTRClvkB/IgYORW2tTtO/t2UL6JwsYdza0bxn:CAWtKZLP6nc+fBdRClO/IgH/ct9OJzKr

Entry address:
0xB6EE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.6930

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
38 KB (38,912 bytes)

Remove phnbabtbgy.exe - Powered by Reason Core Security