installer_java_dutch.exe

Click To Start

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application installer_java_dutch.exe by Click To Start has been detected as adware by 19 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. This program installs potentially unwanted software on your PC at the same time as the software you are trying to install, without adequate consent. The installer is marketed through download protals and search ads as the free Oracle Java Runtime but will also install additional software offers which include adware, PUPs and browser toolbars.
Publisher:
Click To Start  (signed and verified)

MD5:
13b929fcdcf539275d328c43c39830b8

SHA-1:
087e4b69a30bd3abbd4aa4dec3fc7b5d84d66727

SHA-256:
0e6e776e5e91d015968a5623a005cb31b6adfd51194c099588f0b85d8eae4219

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/14/2024 9:58:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
MemScan:Application.Bundler.Outbrowse.V
6383508

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.01.21

Avira AntiVirus
APPL/Downloader.Gen
7.11.203.144

AVG
Generic
2016.0.3223

Bitdefender
MemScan:Application.Bundler.Outbrowse.V
1.0.20.100

Dr.Web
Trojan.OutBrowse.51
9.0.1.05190

Emsisoft Anti-Malware
MemScan:Application.Bundler.Outbrowse.V
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BK potentially unwanted application
7.0.302.0

F-Secure
Riskware.MemScan:Application.Bundler.Outbrowse
5.13.68

G Data
MemScan:Application.Bundler.Outbrowse
15.1.24

IKARUS anti.virus
PUA.OutBrowse
t3scan.1.8.6.0

K7 AntiVirus
Unwanted-Program
13.191.14703

Malwarebytes
PUP.Optional.OutBrowse
v2015.01.20.02

McAfee
Program.Adware-OutBrowse.c
16.8.708.2

MicroWorld eScan
MemScan:Application.Bundler.Outbrowse.V
16.0.0.60

NANO AntiVirus
Trojan.Win32.OutBrowse.dlwssj
0.30.0.64812

Reason Heuristics
PUP.ClickToStart
15.1.20.14

Trend Micro House Call
Suspici.202D3B0F
7.2.20

VIPRE Antivirus
Threat.4150696
36694

File size:
564.8 KB (578,392 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_java_dutch.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
12/5/2014 10:30:02 AM

Valid to:
12/6/2015 10:30:02 AM

Subject:
CN=Click To Start, O=Click To Start, L=Dublin, C=IE

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121A4ADB181C788DD5B27571502842584B8

File PE Metadata
Compilation timestamp:
12/5/2009 11:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:50eOx8NsfGVdNXIeV4pBRlz7DdsPDCIlTEE5+++4OA:50Z8NlVHXIeV4TzmDr5++N

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_java_dutch.exe has been seen being distributed by the following URL.

Remove installer_java_dutch.exe - Powered by Reason Core Security