google-chrome.exe

RUN apps forever lld

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application google-chrome.exe by RUN apps forever lld has been detected as adware by 8 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
RUN apps forever lld  (signed and verified)

MD5:
0f760ed679ad3314e9ffa883d1ae9829

SHA-1:
1be0d5a595ca9d1e4407db2c6ac7fd4bfc1268c8

SHA-256:
172a9f11d2e1129e5f6897a949d0e568e6f001619f0fb2a2bbb09610edd8c2a4

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
12/24/2024 4:51:36 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.12

Dr.Web
infected with Trojan.OutBrowse.125
9.0.1.070

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
9.7.0.302.0

herdProtect (fuzzy)
2015.6.17.21

McAfee
Adware-OutBrowse.e
5600.6829

NANO AntiVirus
Trojan.Win32.Generic.dorbni
0.30.0.296

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.18.1

Trend Micro House Call
Suspici.BCA5EDAC
7.2.70

File size:
610 KB (624,600 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\google-chrome.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
2/7/2015 7:00:00 PM

Valid to:
1/27/2016 6:59:59 PM

Subject:
CN=RUN apps forever lld, O=RUN apps forever lld, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
770A121C72F82874561F320EBFA576A6

File PE Metadata
Compilation timestamp:
12/5/2009 5:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:nB0yOCyP2RAeM74bhmxgay0/prncrBCPBMUT/XaVmWoqz:nBdoYAXPvxrcrBCPBF/KVmm

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9469

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove google-chrome.exe - Powered by Reason Core Security