ccnfd_1_10_0_4.sys

Click Caption Driver x86

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_4.sys by CLICKCAPTION has been detected as adware by 12 anti-malware scanners. It runs as a Windows kernel mode device driver named “ccnfd_1_10_0_4”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x86

Version:
1.10.0.4

MD5:
8081aac9daa4d6cb7c5ca4aaf8d294d2

SHA-1:
892a1f3efcd7eb2651c7ea694af150adab3a61aa

SHA-256:
8175fe2f146552fc38f334a2bafcbf3117d7d5354fa7d38af6b3ee1ab4b16aaa

Scanner detections:
12 / 68

Status:
Adware

Analysis date:
12/25/2024 12:39:26 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Popad
7.1.1

AVG
Clickcaption
2015.0.3263

Dr.Web
Adware.Popad.10
9.0.1.0346

Fortinet FortiGate
Adware/Vitruvian
12/12/2014

IKARUS anti.virus
AdWare.Vitruvian
t3scan.1.8.5.0

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2809

Malwarebytes
PUP.Optional.ClickCaption.A
v2014.12.12.03

McAfee
Artemis!8081AAC9DAA4
5600.6919

Panda Antivirus
Generic Suspicious
14.12.12.03

Qihoo 360 Security
HEUR/QVM00.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.CLICKCAPTION.R
14.12.12.3

Trend Micro House Call
Suspicious_GEN.F47V1207
7.2.346

File size:
51.5 KB (52,728 bytes)

Product version:
1.10.0.4

Copyright:
Copyright (C) 2014

Original file name:
ccnfd.sys

File type:
Driver (Win32 SYS)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_4.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 10:18:53 PM

Valid to:
9/4/2016 10:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/22/2012 2:34:53 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:VB47urAd7AVbTXO2vZd1VjXjurCIDaCCepa+ez8oc3fTtMC5EtX2JHq:L47ue7ITew1JXCrdDqe43cPZf+tsq

Entry address:
0xA085

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 8C, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 08, 8B, 01, 00, B8, 00, 8C, 01, 00, C1, E8, 08, 33, 02, A3, 00, 8C, 01, 00, 75, 07, 8B, C1, A3, 00, 8C, 01, 00, F7, D0, A3, 04, 8C, 01, 00, 5D, E9, 51, E7, FF, FF, CC, 2C, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A8, A4, 00, 00, 94, 8A, 00, 00, 18, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, A4, 00, 00, 80, 8A, 00, 00, 24, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, A4, 00, 00, 8C, 8A, 00, 00, 00...
 
[+]

Code size:
34.8 KB (35,584 bytes)

Driver
Display name:
ccnfd_1_10_0_4

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_4.sys - Powered by Reason Core Security