avg internet security 2015 full license.exe

StArt playing

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application avg internet security 2015 full license.exe by StArt playing has been detected as adware by 22 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup.
Publisher:
StArt playing  (signed and verified)

MD5:
5cf9122ce6d78b5a735c2b3f5550d25a

SHA-1:
11b04a5e3185b9e3faf1515d416857624d737931

SHA-256:
d00a9306c4f2817938310d32eb906abefe4721eb97bec63e5632fda980a708b3

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/15/2024 1:56:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Application.Bundler.Outbrowse.AJ
6458695

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.01.27

Avira AntiVirus
APPL/Outbrowse.Gen
7.11.205.118

avast!
Malware-gen
150101-1

AVG
Downloader
2016.0.3217

Bitdefender
Dropped:Application.Bundler.Outbrowse.AJ
1.0.20.135

Emsisoft Anti-Malware
Dropped:Application.Bundler.Outbrowse.AJ
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BS potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
1/27/2015

F-Secure
Riskware.Dropped:Application.Bundler.Outbrowse
5.13.68

G Data
Dropped:Application.Bundler.Outbrowse.AJ
15.1.25

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.192.14761

Kaspersky
not-a-virus:Downloader.NSIS.OutBrowse
15.0.0.543

Malwarebytes
PUP.Optional.OutBrowse
v2015.01.27.06

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

MicroWorld eScan
Dropped:Application.Bundler.Outbrowse.AJ
16.0.0.81

NANO AntiVirus
Trojan.Win32.OutBrowse.dmxjlz
0.30.0.64812

Reason Heuristics
PUP.Outbrowse
15.1.27.1

Sophos
Generic PUA CC
4.98

Trend Micro House Call
Suspici.1AC582C8
7.2.27

VIPRE Antivirus
Threat.4823950
36694

File size:
572.6 KB (586,312 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\programs\avg internet security 2015 full license.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
1/20/2015 4:00:00 PM

Valid to:
12/11/2015 3:59:59 PM

Subject:
CN=StArt playing, O=StArt playing, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
37FBEB4D120EDCC07BA62BB886A19AF1

File PE Metadata
Compilation timestamp:
12/5/2009 2:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:TZLa1zcFq2t1bmnnJ/fXNlaz6k/To5pgGdHf6r:TZOqFP16nnJ3/amyo5pfJfE

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9700

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove avg internet security 2015 full license.exe - Powered by Reason Core Security