elderscr.exe

Safe Download gtl

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application elderscr.exe by Safe Download gtl has been detected as adware by 25 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent.
Publisher:
Safe Download gtl  (signed and verified)

MD5:
f10f93bbcfa905d7795177e751d71084

SHA-1:
3474a7821e259a138c21f55305f4bad2cc4232bc

SHA-256:
80dcca6d4fe7a906de50fa11d0ac0f50819f30f3f65168edca53ca353ea0b14b

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/10/2024 9:33:44 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.1
686

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.21

Avira AntiVirus
PUA/Outbrowse.Gen
7.11.218.230

avast!
OutBrowse-CX [PUP]
2014.9-150320

AVG
Win.Threat.Medium
2016.0.3164

Bitdefender
Gen:Variant.Application.Bundler.Outbrowse.1
1.0.20.395

Comodo Security
Application.Win32.AltBrowse.HY
21479

Dr.Web
infected with Trojan.OutBrowse.88
9.0.1.079

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Outbrowse
8.15.03.20.08

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/20/2015

F-Secure
Gen:Variant.Application.Bundler
11.2015-20-03_6

G Data
Gen:Variant.Application.Bundler.Outbrowse
15.3.25

herdProtect (fuzzy)
2015.6.26.16

K7 AntiVirus
Trojan
13.202.15333

Malwarebytes
PUP.Optional.OutBrowse.gen
v2015.03.20.08

McAfee
Program.Adware-OutBrowse.e
5600.6820

MicroWorld eScan
Gen:Variant.Application.Bundler.Outbrowse.1
16.0.0.237

NANO AntiVirus
Trojan.Win32.OutBrowse.dnkyzt
0.30.8.659

Quick Heal
Adware.NSIS.OutBrowse.A
6.15.14.00

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.20.20

Trend Micro House Call
Suspici.B3BC0FA9
7.2.79

Vba32 AntiVirus
Downloader.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.4823950
38882

File size:
582.1 KB (596,088 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\elderscr.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
1/27/2015 2:00:00 AM

Valid to:
1/28/2016 1:59:59 AM

Subject:
CN=Safe Download gtl, O=Safe Download gtl, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
14A25C18D3A961BACA6D7C2A3D718B0A

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:bGTwxAJgyjjjFE1fVimC816juNxfjeZgyr2kDaFlHpUDjY/Xr/:b8wx2xjjFE1fMmC1jOfCqjHeY

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9704

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove elderscr.exe - Powered by Reason Core Security