Caramava.FirstRun.exe

FirstRun

Caramava

The Yontoo branded FirstRun executable is distributed as part of a Yontoo product bundle and is desigend to install components of this ad-supported (injection) program as well as 'call home' to inform the server that the extension was installed and may request additional instructions. The application Caramava.FirstRun.exe by Caramava has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Caramava by Yontoo Technology, Inc. which is a potentially unwanted software program.
Publisher:
Caramava  (signed and verified)

Product:
FirstRun

Version:
1.0.0.0

MD5:
c1bbc9873eb5f6f00abfb36f24ca00ec

SHA-1:
2c4298d838f1ce8939d098eb85b539a2e0e8764a

SHA-256:
d946dbd6a3db14bbc6918069440ceb2dc7ee9d833e349fdc25bbacd857f7f672

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
12/25/2024 12:27:19 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.1.23.1

File size:
1.1 MB (1,122,592 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © 2014

Original file name:
Caramava.FirstRun.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\caramava\caramava.firstrun.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/4/2014 3:00:00 AM

Valid to:
2/5/2015 2:59:59 AM

Subject:
CN=Caramava, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Caramava, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00E90CD7C8459392168639C13BC804AE

File PE Metadata
Compilation timestamp:
4/11/2014 8:32:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0x111C3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.9244

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.1 MB (1,113,600 bytes)

The file Caramava.FirstRun.exe has been discovered within the following program.

Caramava  by Yontoo Technology, Inc.
Caramava is an ad-supported (adware) web browser extension that displays popups, banners and injects link ads in the browser. In Internet Explorer it ads a BHO, in Chrome and extension and in Firefox it runs as an add-in that is silently installed.
caramava.com/support
84% remove it
 
Powered by Should I Remove It?

Remove Caramava.FirstRun.exe - Powered by Reason Core Security