rnsc71cf.exe

The application rnsc71cf.exe has been detected as a potentially unwanted program by 13 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Firewall Word Processor by Firewall Word Processor and Zoom In Article by Zoom In Article, both potentially unwanted software. The file has been seen being downloaded from d2htwdv930b0cg.cloudfront.net.
MD5:
c10717dad7303c7d94d966b601e2ea98

SHA-1:
a5738ce5f9b8dbe8cde459a1f7217198886432af

SHA-256:
8e67db89db4358b51a5b2b491e4a6b26176b48fbfb008e2a94d4a855917e59b1

Scanner detections:
13 / 68

Status:
Potentially unwanted

Analysis date:
4/25/2024 2:31:34 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Mikey.11934
653

avast!
Win32:GenMalicious-JXH [Trj]
2014.9-150522

Bitdefender
Gen:Variant.Mikey.11934
1.0.20.565

Emsisoft Anti-Malware
Gen:Variant.Mikey.11934
8.15.04.23.09

ESET NOD32
Win32/Adware.ConvertAd.IH (variant)
9.11617

F-Secure
Gen:Variant.Graftor.184836
11.2015-23-04_5

G Data
Gen:Variant.Mikey.11934
15.4.25

herdProtect (fuzzy)
2015.7.24.16

Kaspersky
UDS:DangerousObject.Multi.Generic
14.0.0.2002

MicroWorld eScan
Gen:Variant.Graftor.184836
16.0.0.339

Reason Heuristics
Threat.Adware.ConvertAd
15.4.23.5

Sophos
Generic PUA NB
4.98

VIPRE Antivirus
Trojan.Win32.Generic
40182

File size:
64.5 KB (66,048 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\00000011-1429791244-0000-0000-10c37bbc672e\rnsc71cf.exe

File PE Metadata
Compilation timestamp:
4/23/2015 6:16:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:r9+SBJ0VRsHiQlXJ5eX1j6ix8g/rkWVQ:dP0VRsHieeA4x/xVQ

Entry address:
0x383D

Entry point:
E8, CD, 38, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 55, 08, 56, 57, 85, D2, 74, 07, 8B, 7D, 0C, 85, FF, 75, 13, E8, AA, 29, 00, 00, 6A, 16, 5E, 89, 30, E8, 4E, 29, 00, 00, 8B, C6, EB, 33, 8B, 45, 10, 85, C0, 75, 04, 88, 02, EB, E2, 8B, F2, 2B, F0, 8A, 08, 88, 0C, 06, 40, 84, C9, 74, 03, 4F, 75, F3, 85, FF, 75, 11, C6, 02, 00, E8, 74, 29, 00, 00, 6A, 22, 59, 89, 08, 8B, F1, EB, C6, 33, C0, 5F, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 5C, 07, 41, 00, 00...
 
[+]

Entropy:
6.0446

Code size:
39.5 KB (40,448 bytes)

The file rnsc71cf.exe has been discovered within the following programs.

Firewall Word Processor  by Firewall Word Processor
This is a WinCheck/CMI (variant) adware/browser hijacker variant that injects code into the user's web browser (IE, Chrome and Firefox).
77% remove it
Zoom In Article  by Zoom In Article
Identified as a version of the CMI/ConvertAd family of malware ad-injectors, this adware which is typically bundled with third-party applications in unwanted software bundles will hijack the user's browser (Internet Explorer, Chrome and Firefox) and display unwanted ads.
74% remove it
 
Powered by Should I Remove It?

The file rnsc71cf.exe has been seen being distributed by the following URL.

Remove rnsc71cf.exe - Powered by Reason Core Security