unconfirmed 837459.torchdownload

Click To Start

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file unconfirmed 837459.torchdownload by Click To Start has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Click To Start  (signed and verified)

MD5:
e3e7155f53aaa902eb183e03de1279af

SHA-1:
7cd735338b75a2148dfad6644b9bb572b2447fe4

SHA-256:
0a2f69990eb8735f1cc4cc55f3218f05039af0a751fd874014fc62296a4eb075

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
4/26/2024 2:02:49 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
MemScan:Application.Bundler.Outbrowse.V
6496598

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.02.01

Avira AntiVirus
APPL/Downloader.Gen
7.11.206.62

AVG
Generic
2016.0.3213

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.15131

Bitdefender
MemScan:Application.Bundler.Outbrowse.V
1.0.20.155

Comodo Security
Application.Win32.OutBrowse.MQPC
20910

Dr.Web
Trojan.OutBrowse.51
9.0.1.05190

Emsisoft Anti-Malware
MemScan:Application.Bundler.Outbrowse.V
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
7.0.302.0

F-Secure
Riskware.MemScan:Application.Bundler.Outbrowse
5.13.68

G Data
MemScan:Application.Bundler.Outbrowse
15.1.25

K7 AntiVirus
Unwanted-Program
13.193.14818

Malwarebytes
PUP.Optional.OutBrowse
v2015.01.31.06

McAfee
Adware-OutBrowse.c
5600.6869

MicroWorld eScan
MemScan:Application.Bundler.Outbrowse.V
16.0.0.93

NANO AntiVirus
Trojan.Win32.OutBrowse.dlwssj
0.30.0.65070

Norman
MemScan:Application.Bundler.Outbrowse.V
02.01.2015 13:58:24

Reason Heuristics
PUP.ClickToStart
15.1.31.6

Sophos
Generic PUA HM
4.98

Trend Micro House Call
Suspici.202D3B0F
7.2.31

VIPRE Antivirus
Threat.4150696
36694

File size:
564.9 KB (578,408 bytes)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\unconfirmed 837459.torchdownload

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/5/2014 11:30:02 AM

Valid to:
12/6/2015 11:30:02 AM

Subject:
CN=Click To Start, O=Click To Start, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A4ADB181C788DD5B27571502842584B8

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:MlOx8NsfGVdNXIeV4pBRlz7DdsPDCIlTEE5+++4O/:MU8NlVHXIeV4TzmDr5++U

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9729

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove unconfirmed 837459.torchdownload - Powered by Reason Core Security