firefox.exe

Ez-download

The Adlogica setup manager, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application firefox.exe by Ez-download has been detected as adware by 18 anti-malware scanners. The program is a setup application that uses the Adlogica Downloader installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. With this installer, users are expecting to download the free Mozilla Firefox web browser but before that occurs they may be presented with additional offers, mostly potentially unwanted software or adware.
Publisher:
Ez-download  (signed and verified)

MD5:
fdfb9ac42386d791265e91600f182803

SHA-1:
faefbdc650f1dc6cb48ff2aa21017c7ca0bda544

SHA-256:
2d8dd7a32b2ed77430033343efebe796a04b5a182e2402236ac176b8fbeb6f3a

Scanner detections:
18 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 12:11:13 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
15.06.18

Avira AntiVirus
PUA/Outbrowse.Gen
7.11.216.56

avast!
Win32:Rootkit-gen [Rtk]
2014.9-150311

AVG
Adware MultiBundle.M
2014.0.4253

Dr.Web
Adware.Downware.2081
9.0.1.070

ESET NOD32
Win32/OutBrowse
9.9675

Fortinet FortiGate
Riskware/OutBrowse
3/11/2015

F-Prot
W32/Outbrowse.B.gen
v6.4.7.1.166

G Data
Win32.Application.OutBrowse
15.3.25

herdProtect (fuzzy)
2015.6.18.4

K7 AntiVirus
Unwanted-Program
13.200.15235

McAfee
Adware-OutBrowse
5600.6829

NANO AntiVirus
Trojan.Win32.Generic.cthmwf
0.28.0.59048

Reason Heuristics
PUP.Bundler.Adlogica
15.3.11.18

Sophos
PUA 'OutBrowse Revenyou'
5.12

Trend Micro House Call
TROJ_GEN.R08OH06D614
7.2.169

VIPRE Antivirus
Trojan.Win32.Generic
28228

File size:
105.1 KB (107,616 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adlogica Downloader (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\firefox.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/13/2013 8:00:00 PM

Valid to:
8/14/2015 7:59:59 PM

Subject:
CN=Ez-download, O=Ez-download, STREET=96 Jessie st 4th floor, L=SAN FRANCISCO, S=CA, PostalCode=94105, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F70CD1FD9DEF6FE1E710D56A167734BD

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:XgXdZt9P6D3XJ+CK5Ky/9XO3jR0eWSzUu/0Wr:Xe34tKUQ9OzRgW/ce

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.6780

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file firefox.exe has been seen being distributed by the following URL.

Remove firefox.exe - Powered by Reason Core Security