Threat Database Adware Adware.Outbrowse.CB

Adware.Outbrowse.CB

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 11,998
Threat Level: 20 % (Normal)
Infected Computers: 472
First Seen: January 7, 2013
Last Seen: June 26, 2026
OS(es) Affected: Windows

The detection of Adware.Outbrowse.CB on your system indicates the presence of a potentially unwanted program that may be causing unwanted advertisements and potentially collecting user data. It is essential to understand the nature of this threat and take immediate action to remove it from your system to prevent further damage.

What Is Adware.Outbrowse.CB?

Adware.Outbrowse.CB is a type of adware program designed to display unwanted advertisements on infected systems. Adware programs like Adware.Outbrowse.CB can be bundled with free software downloads or installed through exploits in web browsers. Once installed, they can collect user data, such as browsing history and search queries, to deliver targeted advertisements.

How Adware.Outbrowse.CB Operates

Adware programs like Adware.Outbrowse.CB typically operate by installing themselves on a system and then connecting to a remote server to download and display advertisements. They may also collect user data, such as browsing history and search queries, to deliver targeted advertisements. In some cases, adware programs can also install additional malware or potentially unwanted programs on the system.

Symptoms of Infection

Systems infected with Adware.Outbrowse.CB may exhibit a range of symptoms, including an increase in unwanted advertisements, slow system performance, and unexpected browser behavior. Users may also notice that their browser homepage or search engine has been changed without their consent. In some cases, adware programs can also cause system crashes or freezes.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Unexpected browser behavior
  • Changed browser homepage or search engine
  • System crashes or freezes

How to Remove Adware.Outbrowse.CB

  1. Boot your system in Safe Mode with Networking to prevent the adware program from loading.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs that may be related to the adware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the adware program.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Adware.Outbrowse.CB from your system is essential to prevent further damage and protect your personal data. By following the steps outlined above, you can remove the adware program and restore your system to a safe and secure state. It is also essential to practice safe browsing habits, such as avoiding suspicious downloads and using reputable anti-malware tools, to prevent future infections.

Analysis Report

General information

Family Name: Adware.Outbrowse.CB
Signature status: No Signature

Known Samples

MD5: 0b62a4c5cd7d3ded58b9c226e587ef44
SHA1: 83cb538c3f7072a4f2960001f950a687e29330ff
SHA256: 31F566968B8E09D6CDCB7FEBFF03C5C875439008E9C3F25ACC40E9DA7449DD99
File Size: 711.33 KB, 711326 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description Installer
Product Version 4.1

File Traits

  • dll
  • HighEntropy
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsbbd3f.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsbbd3f.tmp\frghw.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsbbd3f.tmp\frghw.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\oo2.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\oo2.zzz Generic Write,Read Attributes
c:\users\user\appdata\local\temp\oo2.zzz Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Info Queried
  • GetAdaptersInfo
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpReadData
  • WinHttpReceiveResponse
  • WinHttpSendRequest

Shell Command Execution

C:\Users\Lwauqrhc\AppData\Local\Temp/oo2.exe /PID=5065 /SUBPID=0 /DISTID=21818 /VM=2 /NETWORDK=1 /CID=0 /PRODUCT_ID=21004 /RETURNING_USER_DAYS=2 /SERVER_URL=http://installer.ppdownload.com
wmic /output:C:\Users\Lwauqrhc\AppData\Local\Temp\81770839219.txt bios get serialnumber
wmic /output:C:\Users\Lwauqrhc\AppData\Local\Temp\81770839219.txt bios get version
wmic /output:C:\Users\Lwauqrhc\AppData\Local\Temp\81770839219.txt bios get version
wmic /output:C:\Users\Lwauqrhc\AppData\Local\Temp\81770839219.txt bios get version
Show More
wmic /output:C:\Users\Lwauqrhc\AppData\Local\Temp\81770839219.txt bios get version

Related Posts

Trending

Most Viewed

Loading...