clickcaption-setup-1.10.0.6.exe

Click Caption

CLICKCAPTION

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application clickcaption-setup-1.10.0.6.exe, “Click Caption Setup” by CLICKCAPTION has been detected as adware by 10 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory.
Publisher:
CLICKCAPTION  (signed and verified)

Product:
Click Caption

Description:
Click Caption Setup

Version:
1.10.0.6

MD5:
fd9b3eb82198253ea315de9fd92888da

SHA-1:
a6de399ea4d7116c5cc3941401b180fb0a7867ef

SHA-256:
e28c2e06d5700267c931c30b7c27c5ec0b643c909f60151e01b5122182fa1c7b

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
11/5/2024 4:34:34 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Popad
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen7
7.11.200.12

AVG
Clickcaption
2016.0.3231

Dr.Web
Adware.Popad.11
9.0.1.012

ESET NOD32
Win32/AdWare.Vitruvian (variant)
9.10982

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2652

Malwarebytes
PUP.Optional.ClickCaption.A
v2015.01.12.01

Reason Heuristics
PUP.Installer.CLICKCAPTION.Y
15.1.12.13

Vba32 AntiVirus
AdWare.Vitruvian
3.12.26.3

Zillya! Antivirus
Backdoor.CPEX.Win32.30054
2.0.0.2028

File size:
1008.7 KB (1,032,872 bytes)

Product version:
1.10.0.6

Copyright:
(c) 2014 ClickCaption

Original file name:
clickcaption-setup.exe

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\3f3d46b4_stp\clickcaption-setup-1.10.0.6.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/4/2014 8:18:53 PM

Valid to:
9/4/2016 8:18:53 PM

Subject:
E=support@clickcaption.com, CN=CLICKCAPTION, O=CLICKCAPTION, L=Dover, S=DE, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121F77BE8577127D022B4D9CE6DA92A6C1F

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:06 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:1QolzaOLisBwUb/7MEkA69PI8f70Rqnt2NpRDuaJkiL:Solz39UFh9Axqnt2NpRS

Entry address:
0x323C

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 30, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 58, 6F, 44, 00, E8, 09, 2C, 00, 00, A3, A4, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 58, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, B8, 91, 40, 00, 68, A0, 2E, 44, 00, E8, BC, 28, 00, 00, FF, 15, B0, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, AA, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

Remove clickcaption-setup-1.10.0.6.exe - Powered by Reason Core Security