ccnfd_1_10_0_6.sys

Click Caption Driver x86

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_6.sys by CLICKCAPTION has been detected as adware by 14 anti-malware scanners. It runs as a Windows kernel mode device driver named “ccnfd_1_10_0_6”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x86

Version:
1.10.0.6

MD5:
10027acd41ea02661f69c89212987fbc

SHA-1:
11911b664e61d18eafa9aa000c195f793a9a1d3b

SHA-256:
17e28047cdc7547a66bdbb43efe14f0954b4af1f39538d1874b655337e4debf7

Scanner detections:
14 / 68

Status:
Adware

Analysis date:
1/12/2025 5:20:25 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Popad
7.1.1

Avira AntiVirus
Adware/Vitruvian.52728.1
7.11.200.132

AVG
Clickcaption
2016.0.3231

Dr.Web
Adware.Popad.10
9.0.1.012

Fortinet FortiGate
Adware/Vitruvian
1/12/2015

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2652

Malwarebytes
PUP.Optional.ClickCaption.A
v2015.01.12.02

McAfee
Artemis!10027ACD41EA
5600.6887

Panda Antivirus
Generic Suspicious
15.01.12.02

Qihoo 360 Security
HEUR/QVM00.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.CLICKCAPTION.R
15.1.12.14

Trend Micro House Call
Suspicious_GEN.F47V0108
7.2.12

Vba32 AntiVirus
AdWare.Vitruvian
3.12.26.3

Zillya! Antivirus
Backdoor.CPEX.Win32.30054
2.0.0.2032

File size:
51.5 KB (52,728 bytes)

Product version:
1.10.0.6

Copyright:
Copyright (C) 2015

Original file name:
ccnfd.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_6.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 2:18:53 PM

Valid to:
9/4/2016 2:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/21/2012 6:34:53 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:Vq47urAd7AVbTXO2vZd1VjXjurCIDaCCepa+ez8oc3fTVSC5EtQ2JH7:847ue7ITew1JXCrdDqe43cPRF+th7

Entry address:
0xA085

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 8C, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 08, 8B, 01, 00, B8, 00, 8C, 01, 00, C1, E8, 08, 33, 02, A3, 00, 8C, 01, 00, 75, 07, 8B, C1, A3, 00, 8C, 01, 00, F7, D0, A3, 04, 8C, 01, 00, 5D, E9, 51, E7, FF, FF, CC, 2C, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A8, A4, 00, 00, 94, 8A, 00, 00, 18, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, A4, 00, 00, 80, 8A, 00, 00, 24, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, A4, 00, 00, 8C, 8A, 00, 00, 00...
 
[+]

Entropy:
6.2954

Code size:
34.8 KB (35,584 bytes)

Driver
Display name:
ccnfd_1_10_0_6

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_6.sys - Powered by Reason Core Security