google-chrome.exe

Fast Downloads

The Adlogica setup manager, an installer that bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application google-chrome.exe by Fast Downloads has been detected as adware by 7 anti-malware scanners. The program is a setup application that uses the Adlogica Downloader installer. The setup routine uses the RevenYou.Com Pay Per Install platform (OutBrowse) which bundles additional software offers inclduing toolbars, extensions, PC utilities as well as other PUPs. The installer is marketed through download protals and search ads as Google's Chrome web browser but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Fast Downloads  (signed and verified)

MD5:
d246033ff4606a27cd3d2e8909c46848

SHA-1:
af1f41cec8e543a4fac8daafd0dfd64896cd678e

SHA-256:
c0dc693731b78a132e653eedc10ea557bcb2905bc2858377da1287b425e1222f

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/23/2024 9:04:23 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.OutBrowse
2014.12.15

Avira AntiVirus
APPL/Downloader.Gen
7.11.195.126

AVG
Generic
2015.0.3260

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
7.0.302.0

McAfee
Program.Adware-OutBrowse.c
16.8.708.2

Reason Heuristics
PUP.FastDownloads.N
14.12.14.22

VIPRE Antivirus
Threat.4786018
35418

File size:
576.8 KB (590,672 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Adlogica Downloader (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\google-chrome.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
8/11/2014 7:00:00 PM

Valid to:
8/11/2017 6:59:59 PM

Subject:
CN=Fast Downloads, O=Fast Downloads, STREET="96 Jessie St, 4th Floor", L=San Francisco, S=CA, PostalCode=94105, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FAF54737027D796BDFDF9DFF5F8D1709

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:yYFjdEOPy40CyKB0/AzhMWg3ksAte14ZattLz3oS+oNjVbnAahOTW//D:yijGK0+y73b71MEJLoS+oNjVb/8Ir

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9735

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file google-chrome.exe has been seen being distributed by the following URL.

Remove google-chrome.exe - Powered by Reason Core Security