ccnfd_1_10_0_9.sys

Click Caption Driver x64

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file ccnfd_1_10_0_9.sys by CLICKCAPTION has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows 64-bit kernel mode device driver named “ccnfd_1_10_0_9”.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption Driver x64

Version:
1.10.0.9

MD5:
ca7ba17828d15ead9fdb0e28ccea7aa0

SHA-1:
31a3a06cae7ab08979437e99e9f2877c18d72d3d

SHA-256:
fbcdb075c1243f3fe40314bcf6373497c829785a05960d38126c772f61584d21

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/5/2024 4:45:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InfoAtoms.CLICKCAPTION (M)
16.3.3.18

File size:
56.9 KB (58,232 bytes)

Product version:
1.10.0.9

Copyright:
Copyright (C) 2015

Original file name:
ccnfd.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\ccnfd_1_10_0_9.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 11:18:53 PM

Valid to:
9/4/2016 11:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
8/22/2012 3:34:56 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
1536:kiBIL6sCyo5oIUo0I77nPaXq4Fs+hMeGlDOtcRnjWw:RC6sCysD7L+Fs+hYOtcRnjWw

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Entropy:
6.3816

Code size:
44 KB (45,056 bytes)

Driver
Display name:
ccnfd_1_10_0_9

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove ccnfd_1_10_0_9.sys - Powered by Reason Core Security