ravenbleusacb.exe

Pinball Corporation.

The application ravenbleusacb.exe has been detected as a potentially unwanted program by 30 anti-malware scanners. This file is typically installed with the program RavenBleu by Pinball Corporation which is a potentially unwanted software program.
Publisher:
Pinball Corporation.

Version:
1.0.13.0

MD5:
108df2be364ec7c3e9417cb7caf9aadf

SHA-1:
cb0703e409bbd28c7041cbc66ad074b34a39a25f

SHA-256:
ded374297284ce9a524743d9d9730bfd7a787bebc0cf7acf4dabfd55a8c05d2f

Scanner detections:
30 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 5:52:28 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.qu0@RWPqswfi
865

Agnitum Outpost
Adware.Agent
7.1.1

AhnLab V3 Security
Trojan/Win32.HDC
2012.08.09

Avira AntiVirus
Adware/Hotbar.A.277
7.11.39.68

avast!
Win32:HotBar-CB [Adw]
2014.9-140912

AVG
Skodna.Generic_r
2015.0.3353

Bitdefender
Gen:Adware.Heur.qu0@Ry0dJXni
1.0.20.1275

Bkav FE
W32.Cloda02.Trojan
1.3.0.4613

Boost by Reason
Optional.PinballCorporation.N
188838

Clam AntiVirus
Win.Adware.Agent-4665
0.98/18155

Comodo Security
UnclassifiedMalware
13184

Emsisoft Anti-Malware
AdWare.Win32.HotBar!IK
8.14.09.12.04

ESET NOD32
Win32/Adware.180Solutions
8.9256

Fortinet FortiGate
W32/SPNR.0BFD12!tr
9/12/2014

F-Secure
Gen:Adware.Heur.qu0@Ry0dJXni
11.2014-12-09_6

G Data
Gen:Adware.Heur.qu0@Ry0dJXni
14.9.22

IKARUS anti.virus
AdWare.Win32.HotBar
t3scan.1.1.122.0

K7 AntiVirus
Riskware
13.145.7456

Malwarebytes
Adware.HotBar.Gen
v2014.09.22.01

McAfee
Artemis!108DF2BE364E
5600.7009

Microsoft Security Essentials
Adware:Win32/Hotbar
1.163.1557.0

MicroWorld eScan
Gen:Adware.Heur.qu0@RWPqswfi
15.0.0.795

Norman
W32/Suspicious_Gen5.ECUG
11.20140912

Quick Heal
AdWare.Hotbar (Not a Virus)
9.14.12.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.13

Sophos
Generic PUA MD
4.96

SUPERAntiSpyware
Adware.Agent/Gen-Pinball
10364

Trend Micro House Call
TROJ_SPNR.0BFD12
7.2.255

Trend Micro
TROJ_SPNR.0BFD12
10.465.12

VIPRE Antivirus
Trojan.Win32.Generic
25152

File size:
260 KB (266,240 bytes)

Product version:
1.0.13.0

Copyright:
Copyright © 2001-2009 Pinball Corporation. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\ravenbleusa\bin\1.0.13.0\ravenbleusacb.exe

File PE Metadata
Compilation timestamp:
5/23/2012 5:07:36 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:tpohDE3wfcDmz/IMXoT6R0gSTic8opzaYvxmI74:ohAgf+mz/IkoT6ROTic8oPJf

Entry address:
0x1BB2A

Entry point:
E8, 71, 75, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 78, 5E, 43, 00, 89, 0D, 74, 5E, 43, 00, 89, 15, 70, 5E, 43, 00, 89, 1D, 6C, 5E, 43, 00, 89, 35, 68, 5E, 43, 00, 89, 3D, 64, 5E, 43, 00, 66, 8C, 15, 90, 5E, 43, 00, 66, 8C, 0D, 84, 5E, 43, 00, 66, 8C, 1D, 60, 5E, 43, 00, 66, 8C, 05, 5C, 5E, 43, 00, 66, 8C, 25, 58, 5E, 43, 00, 66, 8C, 2D, 54, 5E, 43, 00, 9C, 8F, 05, 88, 5E, 43, 00, 8B, 45, 00, A3, 7C, 5E, 43, 00, 8B, 45, 04, A3, 80, 5E, 43, 00, 8D, 45, 08, A3, 8C, 5E, 43...
 
[+]

Entropy:
6.6331

Code size:
163 KB (166,912 bytes)

The file ravenbleusacb.exe has been discovered within the following program.

RavenBleu  by Pinball Corporation
RavenBleu is an ad-supported (users may see additional banner and in-text link advertisements) web browser plugin distributed through various monetization platforms during installation.
www.ravenbleu.com
70% remove it
 
Powered by Should I Remove It?

Remove ravenbleusacb.exe - Powered by Reason Core Security