antivirus avg.exe

Click Yes

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application antivirus avg.exe by Click Yes has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.2secondsfiles.net.
Publisher:
Click Yes  (signed and verified)

MD5:
c52fd65552b5d006d7408dad2dd695d2

SHA-1:
676bfceb67cb2758b645695148f5e07e09bda39a

SHA-256:
d8e1d1bf374e8ab300f977d05dcb2ef30970375519681741fb1f3a3fdb18b771

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/27/2024 9:34:17 AM UTC  (today)

Scan engine
Detection
Engine version

AegisLab AV Signature
AdWare.JS.PricePeep
2.1.4+

Avira AntiVirus
APPL/Downloader.Gen
7.11.182.190

AVG
Potentially harmful program Downloader.CBV
2014.0.4189

ESET NOD32
Win32/OutBrowse.BA
8.10657

Malwarebytes
PUP.Optional.OutBrowse
v2014.11.02.09

McAfee
Artemis!7868ADB1B3EA
5600.6959

Reason Heuristics
PUP.ClickYes.N
14.11.3.21

File size:
572.6 KB (586,296 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\antivirus avg.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
10/21/2014 7:00:12 AM

Valid to:
10/22/2015 7:00:12 AM

Subject:
CN=Click Yes, O=Click Yes, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112179D435052EEAF0AF4A60C93CF0595346

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:oBSABI9eWG49xrLTZ906aKDOTAbIrc4J+fnSmuguRuw:o4j4/4LnnRqTUIrK5uguD

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9775

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file antivirus avg.exe has been seen being distributed by the following URL.

Remove antivirus avg.exe - Powered by Reason Core Security