ccnfd_1_10_0_4.sys

Click Caption Driver x64

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_4.sys by CLICKCAPTION has been detected as adware by 7 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “ccnfd_1_10_0_4”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x64

Version:
1.10.0.4

MD5:
e5d93b0f7aea1f9d7a18fbbeb8d23b00

SHA-1:
1003d4ff2f26d8c57e61f31447429f781b3c601c

SHA-256:
363a67409f0a2399345e6429c6331aa99e1dd6b85e19096f0041435291e9f5ac

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
12/25/2024 1:32:59 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Clickcaption
2015.0.3263

Dr.Web
Adware.Plugin.274
9.0.1.0345

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2811

Malwarebytes
PUP.Optional.ClickCaption.A
v2014.12.11.08

NANO AntiVirus
Riskware.Win64.Vitruvian.djxofx
0.28.6.63850

Panda Antivirus
Generic Suspicious
14.12.11.08

Reason Heuristics
PUP.CLICKCAPTION.R
14.12.11.19

File size:
56.9 KB (58,232 bytes)

Product version:
1.10.0.4

Copyright:
Copyright (C) 2014

Original file name:
ccnfd.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_4.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 2:18:53 PM

Valid to:
9/4/2016 2:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/21/2012 6:34:56 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:UiBIL6sCyo5oIUo0I77nPaXq4Fs+hMeGlDOtcRntlu:BC6sCysD7L+Fs+hYOtcRntlu

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Entropy:
6.3821

Code size:
44 KB (45,056 bytes)

Driver
Display name:
ccnfd_1_10_0_4

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_4.sys - Powered by Reason Core Security