setup.exe

OUTBROWSE

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application setup.exe by OUTBROWSE has been detected as adware by 17 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
OUTBROWSE  (signed and verified)

MD5:
f65cbd072716b9b5bb148ba7d7f9fe93

SHA-1:
f8c6ad25f9bd87eb1b48c5a8c6000855cc2d2d8c

SHA-256:
5a20e36b4cd93ce59840618b621ef85b0ee10f11efd1cf62081d9a7c48e6d1a3

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
4/25/2024 6:16:04 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

Avira AntiVirus
APPL/OutBrowse.lwasp
7.11.182.172

AVG
Generic
2015.0.3304

Dr.Web
Adware.Downware.2081
9.0.1.0304

Fortinet FortiGate
Riskware/OutBrowse
10/31/2014

F-Prot
W32/Outbrowse.B.gen
v6.4.7.1.166

G Data
Win32.Application.Outbrowse
14.10.24

K7 AntiVirus
Unwanted-Program
13.185.13866

Kaspersky
not-a-virus:AdWare.Win32.OutBrowse
14.0.0.3016

Malwarebytes
PUP.Optional.OutBrowse
v2014.10.31.07

McAfee
Adware-OutBrowse
5600.6960

NANO AntiVirus
Trojan.Win32.Generic.cthmwf
0.28.6.62995

nProtect
Trojan-Clicker/W32.OutBrowse.993760
14.10.31.01

Qihoo 360 Security
Malware.QVM06.Gen
1.0.0.1015

Reason Heuristics
PUP.Installer.OUTBROWSE.F
14.10.31.19

Sophos
OutBrowse Revenyou
4.98

VIPRE Antivirus
Trojan.Win32.Generic
34414

File size:
970.5 KB (993,760 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
4/7/2014 10:00:00 AM

Valid to:
4/8/2015 9:59:59 AM

Subject:
CN=OUTBROWSE, O=OUTBROWSE, STREET=Bialik Number: 143, L=Ramat Gan, S=Israel, PostalCode=5252337, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A5F03C3A375C11FD6C1C160EE8BFF923

File PE Metadata
Compilation timestamp:
12/6/2009 8:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:cZ/5K0vqxgYznk68rlyJQy0jjSQfEKLKrEewtkPbgwVDTZmxAT7:A5rvyk68Eay0/SQff2rEewtkPbVVvZi0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9271

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove setup.exe - Powered by Reason Core Security