removewat.exe

STarT PLayInG

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application removewat.exe by STarT PLayInG has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
KXFBW  (signed by STarT PLayInG)

Product:
KXFBW

Version:
8632.1568.800.2717

MD5:
b5ba14c030686108a523020799f55948

SHA-1:
660d7d123d4fbc9f0fdbfe90926a5f056af81005

SHA-256:
0cf18d43213b8f80f77b1fbaeb8790f1c8fe7ac59de1859a32868f0a968749f8

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/23/2024 8:17:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.11.25.1

File size:
768.3 KB (786,784 bytes)

Product version:
8632.1568.800.2717

Copyright:
KXFBW

Trademarks:
KXFBW

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou (using Nullsoft Install System)

Language:
Language Neutral

Common path:
C:\Program Files\removewat\removewat.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/4/2015 7:00:00 AM

Valid to:
12/12/2015 6:59:59 AM

Subject:
CN=STarT PLayInG, O=STarT PLayInG, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
0A25F4043B5AFC037A5D8F8F38A4E11A

File PE Metadata
Compilation timestamp:
12/6/2009 5:52:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ZtnCjI/geuvShMuAE83X+3t88Uf4HNYYwIx//FL/HNSqD80Zkdfc8vy4hG:ZMUoDvyfAd3XOt8lAHNRwOnFj8Q86h

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.9711

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

Remove removewat.exe - Powered by Reason Core Security