windowsloader 2.2.2.exe

File

trusted apps ddd

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The application windowsloader 2.2.2.exe by trusted apps ddd has been detected as adware by 20 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. The file has been seen being downloaded from get.0121a.info.
Publisher:
trusted apps ddd  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
aceb76ce9aaf0fed77e197510ecaa7fb

SHA-1:
c9f8d9da31644eb9e4f2b7e90e79b251e2c5ee08

SHA-256:
164de4f41f29f16d229cc8ef8c81cf65877eb4b4a5eeb9add6586ba6cd6917c1

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This is also known as bundleware, or downloadware, which is an downloader designed to simply deliver ad-supported offers in the setup routine of an otherwise legitimate software.

Analysis date:
11/28/2024 2:45:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Dropped:Adware.Generic.1229084
5690745

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.04.25

AVG
Potentially harmful program Downloader.FUG
2014.0.4311

Bitdefender
Dropped:Adware.Generic.1229084
1.0.20.570

Emsisoft Anti-Malware
Dropped:Adware.Generic.1229084
9.0.0.4799

ESET NOD32
Win32/OutBrowse.BU potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
4/24/2015

F-Secure
Adware.Generic.1229084
11.2015-24-04_6

G Data
Dropped:Adware.Generic.1229084
15.4.25

Malwarebytes
PUP.Optional.OutBrowse
v2015.04.24.08

McAfee
Program.Adware-OutBrowse.e
16.8.708.2

MicroWorld eScan
Dropped:Adware.Generic.1229084
16.0.0.342

NANO AntiVirus
Trojan.Win32.OutBrowse.dqucfx
0.30.20.1219

nProtect
Dropped:Adware.Generic.1229084
15.04.24.01

Quick Heal
Adware.NSIS.OutBrowse.A
4.15.14.00

Reason Heuristics
Threat.Outbrowse.Bundler
15.4.24.14

Sophos
Generic PUA LD
4.98

Trend Micro House Call
Suspici.F200210F
7.2.114

VIPRE Antivirus
Threat.5085447
39354

File size:
1.1 MB (1,101,544 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015Apr20-144107-27758679-9e9d-4026-b8d8-055583627e95.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\windowsloader 2.2.2.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
4/15/2015 8:00:00 PM

Valid to:
1/27/2016 6:59:59 PM

Subject:
CN=trusted apps ddd, O=trusted apps ddd, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
04129DCF44442CD28F29F5D7D1910744

File PE Metadata
Compilation timestamp:
4/20/2015 10:41:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:/bSaE4mvt/X1/2XZF3rW7Xd0+ZT+o5VQPXqW6GO:/bSv4mvx12FIXSy6o5yPXqW6

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

The file windowsloader 2.2.2.exe has been seen being distributed by the following URL.

Remove windowsloader 2.2.2.exe - Powered by Reason Core Security