turok full game.exe

File

truStEd downLoaD TyY

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application turok full game.exe by truStEd downLoaD TyY has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the OutBrowse Revenyou installer.
Publisher:
truStEd downLoaD TyY  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
154c186879ecc8ee6d2c254466a66aee

SHA-1:
2ce7bd9063085c08ce7209c25a0afd581eb0ef9e

SHA-256:
53dcd12736d4d10c62cd98d5e4bd6fa95990e7919c522f78351011fb84641122

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
11/30/2024 11:13:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Outbrowse (M)
16.7.15.10

File size:
1.1 MB (1,141,208 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Mar26-152914-49f00474-ae7d-473f-886d-1aa829eb0df3.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\turok full game.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
3/23/2015 1:00:00 AM

Valid to:
1/28/2016 12:59:59 AM

Subject:
CN=truStEd downLoaD TyY, O=truStEd downLoaD TyY, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
76ED39C85E742023973EA7F67D577718

File PE Metadata
Compilation timestamp:
3/26/2015 4:29:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:jMiy4IadS4ms5I6e66fEheKh7sssMqPy/JzWH0tdJ0JhPucfKD8rb89wi20FkCeA:jbSaE4mvt/2Jh0KotucfKwrWwi2IPfc

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove turok full game.exe - Powered by Reason Core Security