ccnfd_1_10_0_6.sys

Click Caption Driver x64

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_6.sys by CLICKCAPTION has been detected as adware by 6 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “ccnfd_1_10_0_6”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x64

Version:
1.10.0.6

MD5:
b6a66d4ea8acc2b284d898f0a372846c

SHA-1:
072d5ae5f85ff5c4e8076f7cf2b11371198664d0

SHA-256:
49e131514a308583a93d6c0c59e9e15a0ab7705a9ed41493242f9ed6a56ec9f0

Scanner detections:
6 / 68

Status:
Adware

Analysis date:
12/25/2024 12:48:50 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Clickcaption
2016.0.3231

Dr.Web
Adware.Plugin.274
9.0.1.012

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2652

Malwarebytes
PUP.Optional.ClickCaption.A
v2015.01.12.03

Panda Antivirus
Generic Suspicious
15.01.12.03

Reason Heuristics
PUP.CLICKCAPTION.R
15.1.12.15

File size:
56.9 KB (58,232 bytes)

Product version:
1.10.0.6

Copyright:
Copyright (C) 2015

Original file name:
ccnfd.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_6.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 8:18:53 PM

Valid to:
9/4/2016 8:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/22/2012 12:34:56 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:oiBIL6sCyo5oIUo0I77nPaXq4Fs+hMeGlDOtcRnl2p:9C6sCysD7L+Fs+hYOtcRnl2p

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Code size:
44 KB (45,056 bytes)

Driver
Display name:
ccnfd_1_10_0_6

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_6.sys - Powered by Reason Core Security