coolwaremax face off max 3.6.2.8 full version setup.exe

staRT noW

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application coolwaremax face off max 3.6.2.8 full version setup.exe by staRT noW has been detected as adware by 11 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
SJJMP  (signed by staRT noW)

Product:
SJJMP

Version:
9050.15526.794.3280

MD5:
a863b3ebd9bed3d33d038c553ee4634f

SHA-1:
10eb68cccb9247907f79cc931401fc29f045cfb9

SHA-256:
49ca18fb09338f2f4c4ee15f0921051d96adf11b75c2ab5eb933151cc53a5066

Scanner detections:
11 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 4:58:42 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BI
5558769

Bitdefender
Application.Bundler.Outbrowse.BI
1.0.20.730

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BI
10.0.0.5366

ESET NOD32
Win32/OutBrowse.CB potentially unwanted application
7.0.302.0

F-Secure
Application.Bundler.Outbrowse
11.2015-26-05_3

G Data
Application.Bundler.Outbrowse.BI
15.5.25

McAfee
Artemis!59FCB555048F
5600.6753

MicroWorld eScan
Application.Bundler.Outbrowse.BI
16.0.0.438

NANO AntiVirus
Trojan.Win32.OutBrowse.drojhb
0.30.24.1636

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Outbrowse.Bundler
15.5.26.18

File size:
635.5 KB (650,736 bytes)

Product version:
9050.15526.794.3280

Copyright:
SJJMP

Trademarks:
SJJMP

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\coolwaremax face off max 3.6.2.8 full version setup.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/26/2015 1:00:00 AM

Valid to:
12/11/2015 11:59:59 PM

Subject:
CN=staRT noW, O=staRT noW, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
7366E562FB25003E03E4582E9B8F157F

File PE Metadata
Compilation timestamp:
12/5/2009 10:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:NralzlY0nBtSM8RNPJuwWFHwg5mzAsvVwrGN8a0zVjHCIfOfc8vy4he:Nralzl1BtXmJuw8X5mlOGN89zRHCIfrr

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9716

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file coolwaremax face off max 3.6.2.8 full version setup.exe has been seen being distributed by the following URL.