click To Start

Publisher Information

click To Start is a software publisher located in Dublin, Ireland*. The company is a primary distributor of unwanted software. Thre are 20 additional code signing certificates issued to this publisher.
Authority:
thawte, Inc.

Valid from:
1/25/2015 7:00:00 AM

Valid to:
12/18/2015 6:59:59 AM

Subject:
CN=click To Start, O=click To Start, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
3c048536baa7e98a4341cf139ee38b14

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Threat.Outbrowse.Bundler, PUP.Outbrowse.clickToStart.Bundler (M), PUP.Outbrowse.clickToS.Bundler (M), PUP.Outbrowse (M), PUP.Outbrowse.Bundler
100.00%

McAfee
Artemis!26B02849BA8E, Program.Adware-OutBrowse.e
6.90%

NANO AntiVirus
Trojan.Win32.KillFiles.dmtzdt, Trojan.Win32.OutBrowse.dnberq
6.90%

Dr.Web
Trojan.KillFiles.22265, infected with Trojan.OutBrowse.78
6.90%

AhnLab V3 Security
PUP/Win32.OutBrowse
6.90%

ESET NOD32
Win32/OutBrowse.BA (variant), Win32/OutBrowse.BU potentially unwanted
6.90%

Baidu Antivirus
PUA.Win32.OutBrowse
3.45%

VIPRE Antivirus
Threat.4150696
3.45%

avast!
OutBrowse-FN [PUP]
3.45%

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BA
3.45%

1 / 68      (Adware)
preconfig.exe  (500a56d213db291519cfd449d4231023)

1 / 68      (Adware)
java_runtime_enviroment_setup.exe.exe  (e77bf7b9befbdbf2ed9ff62c1b4ea75b)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (60bb4e515d0e27a20d4cd4e26855e507)

1 / 68      (Adware)
zekton bold font.exe  (60ac3f6ddb1281fb6e6d5deed2e53c8b)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (1956f1a3d8a7b6735fd8f554b84c190a)

1 / 68      (Adware)
free-maplestory-cheats-codes-hack-download.exe  (3621d51b0e2b11df0f7de1b0535f2acd)

1 / 68      (Adware)
free-maplestory-cheats-codes-hack-download.exe  (709e40d12b1f83cc148c678d41eed066)

1 / 68      (Adware)
free-maplestory-cheats-codes-hack-download.exe  (deb58bb227a58796c247e04cc3813d13)

1 / 68      (Adware)
java_runtime_enviroment_setup.exe.exe  (7bd97c8b05f6ce8757f938d4d171d373)

1 / 68      (Adware)
5c0f.tmp  (d190dc60324ff13ed361e25a8a18a5c8)

1 / 68      (Adware)
installation.exe  (3c829d3b653c8dc0c587c4590ddebf0f)

1 / 68      (Adware)
installation.exe  (9674b5e7ec1d181878c06c8f47558fa3)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (354efef6325bb03b5e0a1ac4058da99f)

1 / 68      (Adware)
installation.exe  (9038a77bafc32b6ebe3481b7f04f152a)

1 / 68      (Adware)
flvplayer4free.exe  (1d70cb7922e04d643de50bf07e8a4963)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (3dfe39fcbf19d4cf86c87908b6261687)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (acec0aba6932010698a00cccdc9ad900)

1 / 68      (Adware)
setup full crack.exe  (4d4b4ea6aa39c44a1d5fb4572d1f3510)

1 / 68      (Adware)
setup full crack.exe  (4ce3ea272113760d8f58d1e2b8c49bd3)

1 / 68      (Adware)
setup full crack.exe  (0c05c8be2810151447cc5d5b73aa6692)

1 / 68      (Adware)
setup full crack.exe  (1f615ba689d4b22b45f6c88290c122b0)

1 / 68      (Adware)
download setup key.exe  (d4208b2e76a57513c8d3b6f3fafea0fa)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (169add2ff68885da228bee41e63734b8)

1 / 68      (Adware)
installation.exe  (18f6e77448d3ca9faed7aff4093c0592)

1 / 68      (Adware)
arabseed.com.elqot.dvdscr.mkv.exe  (4fe76db2884b3492d2cdabf9fa07c062)

1 / 68      (Adware)
vlc-2.1.6a-win32setup.exe  (d587829ffe5b96cc671289608fcb01f0)

1 / 68      (Adware)
java_runtime_enviroment_setup.exe.exe  (ee1414837feda2f186beb5aa6cbfacfc)

24 / 68    (Adware)
kmspico_10.0.3.exe  (451b6c329a14b19ab7708e1fcb39ef73)

7 / 68      (Adware)
bcgcabfdjbah.exe  (26b02849ba8e1c7b1b1c6a11dc7c8da7)

Downloads URLs for files signed by click To Start.

1 / 68      (Adware)

The following websites host and distribute files published by click To Start.

The certificates below are also signed by click To Start.

23B81FD0F7CC52D0FC82EB7B15F6DAE8  (Sep 08, 2015 to Dec 18, 2015)

37D9E505BF19699767562A9E46FA22AE  (Oct 29, 2015 to Dec 18, 2015)

00FD417D76616773057D5038044A4722  (Jun 11, 2015 to Dec 18, 2015)

2DCFF1B0E606917EF69C909299668135  (Jun 30, 2015 to Dec 18, 2015)

63D41C853E9FA7EFE4FF93EA0102CD0B  (Mar 10, 2015 to Dec 18, 2015)

1686670BD7854E0AFD8B17E9A265FBAB  (Dec 17, 2014 to Dec 18, 2015)

4F3BE44946324B1AD2F476F75541A7E7  (Jan 07, 2015 to Dec 18, 2015)

39A49760E2AEE5BC52781521EC87DBCB  (Jun 08, 2015 to Dec 18, 2015)

7E5FC40D076391E0ED7792C5F09A5A94  (Apr 05, 2015 to Dec 17, 2015)

0E95C3AC9D8982FA70D90F1D9D30F857  (Jan 21, 2015 to Dec 17, 2015)

10 of 20 code signing certificates issued

The following publishers (by Authenticode signature organization name) are related.

* Note, the details and description above are based on the code signing digital signature issued to click To Start by thawte, Inc. on January 25, 2015 with the serial number '3c048536baa7e98a4341cf139ee38b14'.