motorola razr xt910 mode.exe

Yes Apps

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application motorola razr xt910 mode.exe by Yes Apps has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.file23desktop.com.
Publisher:
Yes Apps  (signed and verified)

MD5:
33f652c51528322efdc54042a2e16181

SHA-1:
628503d66a4873922921852450b73b8a85f06961

SHA-256:
aa70119d43f562d7c0e7ed3e3fb4a854784d215bf000122b73916838edc7db22

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
12/25/2024 6:37:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Application.Bundler.Outbrowse.1
676

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.03.31

avast!
Rootkit-gen [Rtk]
2014.9-150330

AVG
Potentially harmful program Downloader
2016.0.3154

Bitdefender
Gen:Variant.Application.Bundler.Outbrowse.1
1.0.20.445

Comodo Security
Application.Win32.AltBrowse.HY
21589

Dr.Web
infected with Trojan.OutBrowse.100
9.0.1.089

Emsisoft Anti-Malware
Gen:Variant.Application.Bundler.Outbrowse
8.15.03.30.02

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
9.7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
3/30/2015

G Data
Gen:Variant.Application.Bundler.Outbrowse
15.3.25

K7 AntiVirus
Trojan
13.200.15236

Malwarebytes
PUP.Optional.OutBrowse
v2015.03.30.03

McAfee
Program.Adware-OutBrowse.e
5600.6810

MicroWorld eScan
Gen:Variant.Application.Bundler.Outbrowse.1
16.0.0.267

NANO AntiVirus
Riskware.Win32.OutBrowse.dorbak
0.30.8.659

Quick Heal
Adware.NSIS.OutBrowse.A
3.15.14.00

Reason Heuristics
PUP.Bundler.Outbrowse
15.3.30.14

Trend Micro House Call
Suspici.B4D1CBB0
7.2.89

Vba32 AntiVirus
AdWare.OutBrowse
3.12.26.3

VIPRE Antivirus
Threat.4150696
38552

File size:
576.8 KB (590,688 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
1/27/2015 5:34:38 PM

Valid to:
1/12/2016 6:27:41 PM

Subject:
CN=Yes Apps, O=Yes Apps, L=DUBLIN, C=IE

Issuer:
CN=Starfield Secure Certificate Authority - G2, OU=http://certs.starfieldtech.com/repository/, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
00BBF41B37FA0CDBB9

File PE Metadata
Compilation timestamp:
12/6/2009 12:50:52 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:mYuECOQFFOAeKs1Hf0sxTX1aBtE5hBYqv/gcvy+jLR:mpEVSjejJ0sxTsBtE5E04uF

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9659

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file motorola razr xt910 mode.exe has been seen being distributed by the following URL.

Remove motorola razr xt910 mode.exe - Powered by Reason Core Security