ccnfd_1_10_0_5.sys

Click Caption Driver x64

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_5.sys by CLICKCAPTION has been detected as adware by 5 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “ccnfd_1_10_0_5”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x64

Version:
1.10.0.5

MD5:
fdf309ba1e7fa4b46271fac6ebd747e2

SHA-1:
be98ae6e115285009a6690de6ae7087da78f69f4

SHA-256:
bb42711d0b2935d036004148e44476c4d2f7a91ed984603edf0ee3fb1f53b5f5

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
12/25/2024 12:53:18 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Clickcaption
2015.0.3250

Dr.Web
Adware.Plugin.274
9.0.1.0358

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2745

Malwarebytes
PUP.Optional.ClickCaption.A
v2014.12.24.11

Reason Heuristics
PUP.CLICKCAPTION.R
14.12.24.23

File size:
56.9 KB (58,232 bytes)

Product version:
1.10.0.5

Copyright:
Copyright (C) 2014

Original file name:
ccnfd.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_5.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 2:18:53 PM

Valid to:
9/4/2016 2:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/21/2012 6:34:56 PM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:xiBIL6sCyo5oIUo0I77nPaXq4Fs+hMeGlDOtcRnE9v:sC6sCysD7L+Fs+hYOtcRnE9v

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Code size:
44 KB (45,056 bytes)

Driver
Display name:
ccnfd_1_10_0_5

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_5.sys - Powered by Reason Core Security