Tag Archives: OutBrowse

RUn apps fOrevEr Lld – 35% Detection Rate

Hi there! Just a quick post on a file named Medal Of Honour PC Game Full version Free Download.exe signed by RUn apps fOrevEr Lld.

The following screenshot shows the User Account Control dialog when running the RUn apps fOrevEr Lld file:

RUn apps fOrevEr Lld publisher

It is also possible to check a digital signature by looking at a file’s properties. Here’s a screenshot of the RUn apps fOrevEr Lld certificate.

RUn apps fOrevEr Lld cert

The VirusTotal report shows that the RUn apps fOrevEr Lld file should be avoided, since Medal Of Honour PC Game Full version Free Download.exe is detected as Trojan.OutBrowse.1613 by DrWeb, Downloader.AAPP by AVG, SoftwareBundler:Win32/Outbrowse by Microsoft, OutBrowse by VIPRE and HEUR/QVM42.0.Malware.Gen by Qihoo-360.

RUn apps fOrevEr Lld anti-virus report

Did you also find a file that was digitally signed by RUn apps fOrevEr Lld? What kind of download was it and was it reported by the anti-malware scanners at VirusTotal? Please share by posting a comment.

Thanks for reading.

SaFE clIck LoL – 36% Detection Rate

Welcome! Just wanted to give you the heads up on files digitally signed by SaFE clIck LoL.

SaFE clIck LoL publisher

You will also see SaFE clIck LoL listed as the verified publisher in the User Account Control dialog that pops up if you try to run the file: It’s possible to view additional information about the embedded certificate by right-clicking on the file, choosing properties and then clicking on the Digital Signatures tab. According to the certificate we can see that SaFE clIck LoL appears to be located in Dublin, Ireland and that the certificate is issued by thawte SHA256 Code Signing CA.

SaFE clIck LoL cert

The problem with the SaFE clIck LoL file is that it is detected by many of the antimalware scanners. Here are some of the detection names: Downloader.AAPP, PUA/Outbrowse.Gen, SoftwareBundler:Win32/Outbrowse and OutBrowse.

SaFE clIck LoL anti-virus report

Did you also find an SaFE clIck LoL? Do you remember the download link? Please post it in the comments below and I’ll upload it to VirusTotal to see if that one is also detected.

Thanks for reading.

ClIck to StaRt – 24% Detection Rate – OutBrowse

Hello readers! Just a quick post on a publisher called ClIck to StaRt that I found while running some tests for the upcoming FreeFixer release. The suspicious file is named Animal Porn On Android.exe.

The following screenshot shows the User Account Control dialog when running the ClIck to StaRt file:

ClIck to StaRt publisher

To get more details on the publisher, you can view the certificate by right-clicking on the file, and looking under the Digital Signatures tab.. The screenshot below shows the Click to StaRt certificate. From the certificate info we can see that ClIck to StaRt appears to be located in Dublin, Ireland.

ClIck to StaRt certificate

The reason I’m writing this blog post is that the ClIck to StaRt file is detected by many of the anti-virus software at VirusTotal. AVG reports Luhe.Fiha.A, McAfee reports Adware-OutBrowse.h, Avast names Animal Porn On Android.exe as Win32:Malware-gen, ClamAV detects it as Win.Adware.Outbrowse-1167 and DrWeb detects it as Trojan.OutBrowse.1694.

ClIck to StaRt anti-virus report

Did you also find a ClIck to StaRt file? What kind of download was it? If you remember the download link, please post it in the comments below.

Thanks for reading.

BoxI DJV – 49% Detection Rate – OutBrowse / Downloader.YVA / W32.HfsAdware

Hi there! Ran into a BoxI DJV file about a week ago, but decided not to blog about it since I got the schedule full with other things. I’m currently working on improving the freefixer.com web site with some new features.

However, I changed my mind today about BoxI DJV since there currently a large number of files being distributed with the BoxI DJV signature. And since the Boxl DJV file is detected by many of the anti-virus programs out there I wanted to give you the heads up with a short blog post about it. Here’s BoxI DJV listed as the verified publisher:

BoxI DJV

You can see who the signer is when double-clicking on an executable file. BoxI DJV appears in the publisher field in the dialog that pops up. The certificate is issued by thawte SHA256 Code Signing CA.

Here’s the detections from VirusTotal for BoxI DJV:

BoxI DJV anti-virus report

The detection rate is 26/53. The Moborobo.exe file is detected as OutBrowse by VIPRE, Riskware/OutBrowse by Fortinet, PUA.Boxidjv1.Gen by CAT-QuickHeal, Trojan.OutBrowse.1215 by DrWeb, Downloader.YVA by AVG, W32.HfsAdware.9EC9 by Bkav and SAPE.Heur.BB351 by Symantec.

Did you also find a file digitally signed by BoxI DJV? What kind of download was it and where did you find it?

Thanks for reading.

BEst inSTall TLl – 49% Detection Rate

Hello readers! If you are a regular here on the FreeFixer blog you know that I’ve been looking on the certificates used to sign files that bundled various types of unwanted software. Today I found another certificate, used by a publisher called BEst inSTall TLl.

BEst inSTall TLl publisher

If you have a BEst inSTall TLl file on your machine you may have noticed that BEst inSTall TLl is displayed as the publisher in the UAC dialog when double-clicking on the file. You can also check the digital signature under the file’s properties. According to the embedded certificate we can see that BEst inSTall TLl is located in Dublin, Ireland and that the certificate is issued by thawte SHA256 Code Signing CA.

BEst inSTall TLl certificate

Thawte has issued the certificate.

BEst inSTall TLl cert chain

So, what does the anti-virus programs say about the BEst inSTall TLl file? No problem, I just uploaded the file to VirusTotal and it turned out that many of the anti-virus programs detects the BEst inSTall TLl file, with names such as NSIS:OutBrowse-DQ [PUP], Downloader.QWU, Gen:Variant.Adware.Mikey.21084, HEUR/QVM30.1.Malware.Gen and Generic PUA AA (PUA).

BEst inSTall TLl anti-virus report

Did you also find a BEst inSTall TLl file? What kind of download was it? If you remember the download link, please post it in the comments below.

Thanks for reading.

Update 2015-08-18: Found another download, also signed by Best Install TLl, claiming to be an episode of a famous TV series. The detection rate for this file was 45%. Notice that the installer does not have any button to cancel the installation.

BEst inSTall TLl installer window

COnfirmED APp nLn – 18% Detection Rate – OutBrowse

Hi there! Lately I’ve been looking on the digital signatures on those files that push various types of unwanted programs. This morning I found a new file called Player.exe, digitally signed by COnfirmED APp nLn.

The following screenshot shows the User Account Control dialog when running the COnfirmED APp nLn file:

COnfirmED APp nLn publisher

You can also check the digital signature under the file’s properties. According to the certificate we can see that COnfirmED APp nLn seems to be located in Ireland and that the certificate is issued by thawte SHA256 Code Signing CA.

COnfirmED APp nLn cert

The problem with the COnfirmED APp nLn file is that it is detected by many of the antivirus progams. Here are some of the detection names: Downloader.LIR, PUA.OutBrowse.A and Adware-OutBrowse.g.

COnfirmED APp nLn anti-virus detection

Since you probably came here after finding a file that was signed by COnfirmED APp nLn, please share what kind of download it was and if it was detected by the antivirus scanners at VirusTotal.

Thank you for reading.

OtOPIa Soft – 25% Detection Rate – OutBrowse / Artemis

Hi there! Just wanted to give you the heads up on a publisher called OtOPIa SOft

OtOPIa SOft publisher

You can see who the signer is when double-clicking on an executable file. OtOPIa SOft appears in the publisher field in the dialog that pops up. To view more information about the certificate you can right-click on the file, then choose Properties and then select the Digital Signatures tab. According to the certificate we can see that OtOPIa SOft is located in Dublin, Ireland and that the certificate is issued by thawte SHA256 Code Signing CA.

OtOPIa SOft cert

So, why did I put up this blog post? Well, the thing is that the OtOPIa SOft file is detected by many of the anti-malware scanners, according to VirusTotal. AVG names Player.exe as Downloader.KAM, Malwarebytes calls it Trojan.Inject, McAfee-GW-Edition detects it as Artemis and VIPRE detects it as OutBrowse (fs)

OtOPIa SOft anti-virus report

Did you also find a file signed by OtOPIa SOft? What kind of download was it and where did you find it?

Thanks for reading.

just accepT – 12% Detection Rate – OutBrowse

Hi there! Short on time today, but I just wanted to give you the heads up on a publisher called just accepT.

just accepT publisher

You can see who the signer is when double-clicking on an executable file. just accepT appears in the publisher field in the dialog that pops up. You can also see the just accepT certificate by looking under the Digital Signature tab on the file’s properties. According to the certificate, just accepT is located in Dublin in Ireland.

just accepT certificate

After uploading the just accepT file – Player.exe – to VirusTotal, it was clear that it’s probably better to delete the file than running it. The detection rate was 12% and some of the detection names were: Downloader.HFI and Artemis!83841CFEAEC6.

just accepT virus total

Did you also find a just accepT file?

Thank you for reading.

SaFe SoftwaRe sLL – 30% Anti-Virus Detection – OutBrowse

Welcome! I was playing around and testing some downloads when I found a file signed by SaFe SoftwaRe sLL.

You can see who the signer is when double-clicking on an executable file. SaFe SoftwaRe sLL appears in the publisher field in the dialog that pops up.

SaFe SoftwaRe sLL publisher

You can also check the digital signature under the file’s properties. According to the embedded certificate we can see that SaFe SoftwaRe sLL seems to be located in Ireland and that the certificate is issued by thawte SHA256 Code Signing CA.

SaFe SoftwaRe sLL certificate

 

The certificate is quite new. It’s valid from the 5th of April 2015.

So, why am I writing about the SaFe SoftwaRe sLL file? Check out what the anti-malware scanners report about the file:

SaFe SoftwaRe sLL virus report

AVG names Player.exe as Downloader.FLM, Cyren detects it as W32/Outbrowse.B2.gen!Eldorado, DrWeb names it Trojan.OutBrowse.296, F-Prot detects it as W32/Outbrowse.B2.gen!Eldorado and McAfee calls it Adware-OutBrowse.e are a few of the detection names for Player.exe.

Did you also find a SaFe SoftwaRe sLL file? What kind of download was it? If you remember the download link, please post it in the comments below.

Thanks for reading.

Tiki Taka – 25% Anti-Virus Detection – OutBrowse / Revenyou

Welcome! Just a short post before I call it a day. I found yet another interesting file. It was  was signed by Tiki Taka.

Tiki Taka uac

You may see Tiki Taka appear as the publisher when double-clicking on the Player.exe file. Viewing the certificate information is also possible by looking under the digital signature tab for the file. Here the certificate says that Tiki Taka is located in Dublin, Ireland.

Tiki Taka certificate

I decided to upload the Tiki Taka file to VirusTotal. 25% of the scanners detected the file. PUA/Outbrowse.Gen, Trojan.OutBrowse.68, Win32/OutBrowse.BU potentially unwanted, PUP.Optional.OutBrowse and OutBrowse Revenyou are some of the detection names.

Tiki Taka anti-virus report

Did you also find an Tiki Taka? Do you remember the download link? Please post it in the comments below and I’ll upload it to VirusTotal to see if that one is also detected.

Thank you for reading.