file.exelud4gls0.sis.pendingoverwrite

team_fortress_2_non_steam

TRUstEd DoWnloAD tyy

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file file.exelud4gls0.sis.pendingoverwrite by TRUstEd DoWnloAD tyy has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer. It is also typically executed from the user's temporary directory.
Publisher:
TRUstEd DoWnloAD tyy  (signed and verified)

Product:
team_fortress_2_non_steam

Version:
1.15521.132.0

MD5:
5dccb44daec3cb2a16aaa8046cb198fd

SHA-1:
c155290bea8e110345c0eb754025c927e93c8e96

SHA-256:
e7a759ad770f19441f81575771c07e1a3e4af3a7dbc9215607cfd8ec87f39d7f

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 1:02:19 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
17.1.27.5

File size:
677.5 KB (693,768 bytes)

Product version:
1.15521.132.0

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\appdata\local\temp\file.exelud4gls0.sis.pendingoverwrite

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/18/2015 2:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=TRUstEd DoWnloAD tyy, O=TRUstEd DoWnloAD tyy, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
164C12E03B8E53299F9F15537E339C32

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove file.exelud4gls0.sis.pendingoverwrite - Powered by Reason Core Security