cfcabfijcfe.exe

great apps tld

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application cfcabfijcfe.exe by great apps tld has been detected as adware by 12 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs.
Publisher:
great apps tld  (signed and verified)

Version:
2015.24.859.9

MD5:
e690f3f230e11750bb20dedbb3db39e8

SHA-1:
2316ab24127f09a2e1efe4ea86dacffa1fdbeddb

SHA-256:
430226c1db3fe82161c7858f6719cdf7a9e3a7929f752dc61efc6f00b978f6ea

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/24/2024 4:21:17 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.02.06

AVG
Generic
2016.0.3195

Baidu Antivirus
PUA.Win32.OutBrowse
4.0.3.1525

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.OutBrowse.92
9.0.1.048

ESET NOD32
Win32/OutBrowse.BA potentially unwanted application
7.0.302.0

G Data
Win32.Application.Agent.2NF35Z
15.2.25

K7 AntiVirus
Unwanted-Program
13.193.14895

Qihoo 360 Security
HEUR/QVM10.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Outbrowse
15.2.14.11

Sophos
OutBrowse Revenyou
4.98

VIPRE Antivirus
OutBrowse
37340

File size:
808.7 KB (828,096 bytes)

Product version:
2015.24.859.9

Copyright:
Copyright (C) 2015

Original file name:
2015248599.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\cfcabfijcfe.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
2/5/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=great apps tld, O=great apps tld, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
71A7D3C85E4D6A0DC612379CA6648AB1

File PE Metadata
Compilation timestamp:
2/4/2015 10:02:55 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:b0XfGxTZyTFB0EzGrfn/LJUfXQD/ewwy/MtiQRb8+/Q:b0XfGx1yTFLGbLJEQD/15MtT8+/Q

Entry address:
0x8159B

Entry point:
E8, FA, A9, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 28, D8, 49, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 68, D0, 49, 00, C9, C2, 08, 00, B8, DF, CA, 48, 00, A3, 78, AF, 4B, 00, C7, 05, 7C, AF, 4B, 00, D5, C1, 48, 00, C7, 05, 80, AF, 4B, 00, 89, C1, 48, 00, C7, 05, 84, AF, 4B, 00, C2, C1, 48, 00, C7, 05...
 
[+]

Code size:
622 KB (636,928 bytes)

Remove cfcabfijcfe.exe - Powered by Reason Core Security