beeajdgage.exe

Click Yes

Part of the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application beeajdgage.exe by Click Yes has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Click Yes  (signed and verified)

Version:
2015.830.120.64

MD5:
a93dc71d8f62e3e5d6701ffd6c9c2955

SHA-1:
b28657c3316e7d3a58ac3bf050cbc314e26a65a7

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 3:59:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
17.3.16.0

File size:
938.4 KB (960,936 bytes)

Product version:
2015.830.120.64

Copyright:
x

Original file name:
201583012064.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\beeajdgage.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
1/4/2015 5:58:22 PM

Valid to:
10/22/2015 8:00:12 PM

Subject:
CN=Click Yes, O=Click Yes, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121276DF31F86B383F60209F1B136866206

File PE Metadata
Compilation timestamp:
8/30/2015 9:00:15 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x92C66

Entry point:
E8, ED, DF, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 56, 57, 6A, 08, 59, BE, C4, 48, 4B, 00, 8D, 7D, E0, F3, A5, 8B, 75, 0C, 8B, 7D, 08, 85, F6, 74, 13, F6, 06, 10, 74, 0E, 8B, 0F, 83, E9, 04, 51, 8B, 01, 8B, 70, 18, FF, 50, 20, 89, 7D, F8, 89, 75, FC, 85, F6, 74, 0C, F6, 06, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 64, 30, 4B, 00, 5F, 5E, 8B, E5, 5D, C2, 08, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B...
 
[+]

Entropy:
6.6683

Code size:
709.5 KB (726,528 bytes)

Remove beeajdgage.exe - Powered by Reason Core Security