What is Feven?

Feven is software application developed by Crossrider Advanced Technologies Ltd. (Platform). It is most commonly found on computers running Windows 7 with nearly 66.67% of installations running this operating system. Feven's installer is typically 8.00 MB in size and installs around 44 files. The most common release is 1.33.153.1 with 35.74% of all installations currently using this version.

Feven is most popular in the United States with 25.88% of installations residing in this country.

Feven adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Feven?

Feven is a powerful web browser extension designed to enhance the browsing experience by modifying the search and home pages. It also incorporates features to protect the default browser search engine while generating search advertising revenue. Typically distributed through bundled offers within third-party software, Feven seamlessly integrates into the browser to offer the following functionalities: - Modifying the default search engine, including the browser's built-in search box, and address bar. - Altering the default Home Page and/or New Tabs while safeguarding your search settings. - Adding alternative error page functionality, like "Page Not Found". With Feven, users can customize their browsing preferences while benefitting from an enhanced and streamlined search experience.

Multiple virus scanners have detected malware in Feven.

utils.exe (MD5: dd0a810d4abf6942dcc15cab68d1b21f) has been flagged by 40 scanners:
Scanner Software Result
Bkav FE HW32.CDB
Malwarebytes PUP.Optional.Feven.A
Symantec WS.Reputation
Lavasoft Ad-Aware Adware.Generic.929234
AegisLab W32.Sality
Agnitum Outpost PUA.Toolbar.CrossRider!
avast! Win32:Crossrider-AI [PUP]
AVG Generic5.ANCK
Avira Adware/CrossRider.A.10284
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.T
Bitdefender Adware.Generic.929234
CAT-QuickHeal AdWare.Feven.r5 (Not a Virus)
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.950
Emsisoft Anti-Malware Adware.Generic.929234 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.T
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-f837d5f1!Eldorado
F-Secure Adware.Generic.929234
G Data Adware.Generic.929234
K7 AntiVirus Trojan ( 00494ca01 )
K7GW Trojan ( 00494ca01 )
McAfee Adware-AddLyrics
McAfee-GW-Edition BehavesLike.Win32.AdwareCross.hh
Microsoft Security Essentials Adware:Win32/Feven
MicroWorld-eScan Adware.Generic.929234
NANO AntiVirus Trojan.Win32.Crossrider.cvxsxs
Qihoo-360 Win32/Virus.Adware.d90
Sophos AppRider
Trend Micro TROJ_GEN.R0CBC0CCH14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Lyckriks.Win32.571
Clam AntiVirus Win.Adware.Plush-29
Jiangmin AdWare/Lyckriks.ki
TrendMicro-HouseCall TROJ_GEN.R0CBC0CCH14
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Lyckriks
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Panda Antivirus Trj/CI.A
Feven 1.7-updater.exe (MD5: ddd109d17ff832503060b9a7c2c6ea05) has been flagged by 3 scanners:
Scanner Software Result
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.K
Malwarebytes PUP.Optional.Feven.A
VIPRE Antivirus Crossrider (fs)
Feven 1.7-firefoxinstaller.exe (MD5: f23cbb54a7a79f5f5d522a7948754726) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.2u1@mKdf!qpO
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.Addlyrics
avast! Win32:Crossrider-AI [PUP]
AVG Toolbar.UD
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.2u1@mKdf!qpO
Bkav FE W32.HfsAdware.A7F9
Comodo Security ApplicUnwnt
Cyren W32/A-6583813c!Eldorado
Dr.Web Trojan.Crossrider1.23864
ESET-NOD32 Win32/Toolbar.CrossRider.S potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-6583813c!Eldorado
F-Secure Gen:Application.Heur.2u1@mKdf!qpO
G Data Gen:Application.Heur.2u1@mKdf!qpO
Malwarebytes PUP.Optional.Feven.A
McAfee Adware-AddLyrics
McAfee-GW-Edition Adware-AddLyrics
MicroWorld-eScan Gen:Application.Heur.2u1@mKdf!qpO
NANO AntiVirus Riskware.Win32.Toolbar.czjdfd
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R0C1C0EJB14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJB14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.137
Jiangmin AdWare/Lyckriks.cu
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Feven 1.7-enabler.exe (MD5: 8e1cc90006c32a0ed9cd72b3eed7950a) has been flagged by 42 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.vu1@mS@yIabO
Agnitum Outpost PUA.Agent!
AhnLab-V3 PUP/Win32.Addlyrics
Arcabit Application.Heur.EA19E9
avast! Win32:IeEnablerC-G [Adw]
AVG Generic5.ANHA
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.45
Bitdefender Gen:Application.Heur.vu1@mS@yIabO
Bkav FE W32.HfsAdware.A7F9
CAT-QuickHeal PUA.Feven.A6
Clam AntiVirus Win.Adware.Plush-29
Comodo Security ApplicUnwnt
Cyren W32/S-a64d6097!Eldorado
Dr.Web Trojan.Crossrider1.23864
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.T potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-a64d6097!Eldorado
F-Secure Gen:Application.Heur.vu1@mS@yIabO
G Data Gen:Application.Heur.vu1@mS@yIabO
IKARUS anti.virus AdWare.CrossRider
Jiangmin AdWare/Lyckriks.ki
K7 AntiVirus Adware ( 004bbf581 )
K7GW Adware ( 004bbf581 )
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Feven.A
McAfee Adware-AddLyrics
McAfee-GW-Edition Adware-AddLyrics
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
MicroWorld-eScan Gen:Application.Heur.vu1@mS@yIabO
NANO AntiVirus Trojan.Win32.Toolbar.ctsoci
Rising Antivirus PE:Malware.Adload!6.1D39
Sophos AppRider (PUA)
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R047C0EFG15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Agent.Win32.9493
TrendMicro-HouseCall TROJ_GEN.R0CBC0EBJ15
Vba32 AntiVirus AdWare.Lyckriks
Feven 1.7-codedownloader.exe (MD5: 734a9de172e84812b5dcd91929209a32) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Gu1@mS2ECkmO
Agnitum Outpost PUA.Agent!
AhnLab-V3 PUP/Win32.Addlyrics
Arcabit Application.Heur.E8AAAA
avast! Win32:Crossrider-AI [PUP]
AVG Crossrider.OF
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.Gu1@mS2ECkmO
CAT-QuickHeal PUA.Feven.A6
Comodo Security ApplicUnwnt
Cyren W32/A-eb9ef301!Eldorado
Dr.Web Trojan.Crossrider1.23864
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.T potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
F-Secure Gen:Application.Heur.Gu1@mS2ECkmO
G Data Gen:Application.Heur.Gu1@mS2ECkmO
IKARUS anti.virus AdWare.CrossRider
Jiangmin Adware/Agent.apqp
K7 AntiVirus Trojan ( 004a08ef1 )
K7GW Trojan ( 004a08ef1 )
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
McAfee Adware-AddLyrics
McAfee-GW-Edition Adware-AddLyrics
Microsoft Security Essentials Adware:Win32/Feven
MicroWorld-eScan Gen:Application.Heur.Gu1@mS2ECkmO
NANO AntiVirus Riskware.Win32.Downware.cynnrj
Sophos AppRider
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R047C0CFG15
VIPRE Antivirus Crossrider (fs)
Zillya Backdoor.PePatch.Win32.37980
Bkav FE W32.HfsAdware.A7F9
Malwarebytes PUP.Optional.Feven.A
TrendMicro-HouseCall TROJ_GEN.R0CBC0EBJ15
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks

Software Behaviors

Scheduled tasks:
  • Feven 1.7-firefoxinstaller.exe is scheduled as a task named 'Feven 1.7-firefoxinstaller'.

Startup Entries

Startup tasks:
  • Feven 1.5-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.5-firefoxinstaller.
  • Feven 1.5-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.5-chromeinstaller.
  • Feven 1.5-updater.exe is automatically launched at startup through a scheduled task named Feven 1.5-updater.
  • Feven 1.5-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.5-enabler.
  • Feven 1.5-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.5-codedownloader.
  • Feven 1.7-updater.exe is automatically launched at startup through a scheduled task named Feven 1.7-updater.
  • Feven 1.7-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.7-enabler.
  • Feven 1.7-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.7-codedownloader.
  • Feven 1.7-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.7-firefoxinstaller.
  • Feven 1.7-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.7-chromeinstaller.
  • Feven 1.8-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.8-enabler.
  • Feven 1.8-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.8-chromeinstaller.
  • Feven 1.8-validator.exe is automatically launched at startup through a scheduled task named Feven 1.8-validator.
  • Feven 1.8-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.8-codedownloader.

Software Details

URL:
https://crossrider.com/pages/extension_eula
Support:
–
Installation path:
C:\Program Files\Feven 1.8
Uninstaller:
C:\Program Files\Feven 1.8\Uninstall.exe /fromcontrolpanel=1
Size:
8.00 MB
Language:
English

Feven Executable Details

Primary executable:
utils.exe
Name:
Feven
Path:
C:\Program Files\Feven 1.8\utils.exe
MD5:
dd0a810d4abf6942dcc15cab68d1b21f
SHA-1:
–
SHA-256:
–
Files installed by Feven
File Type Filename MD5
EXE
f6600f316b7c5a5524c3834e192fc39f
EXE
utils.exe
Malware
dd0a810d4abf6942dcc15cab68d1b21f
EXE
5964c8eec3d09ac6a1178667f07b5e22
DLL
e918db44edf328a4d5e29ed4439a9156
DLL
ba9324ee766100a0eb35fbde1f6e590e
EXE
ddd109d17ff832503060b9a7c2c6ea05
EXE
f23cbb54a7a79f5f5d522a7948754726
EXE
8e1cc90006c32a0ed9cd72b3eed7950a
EXE
734a9de172e84812b5dcd91929209a32
EXE
dae355a6fd6182e95576e36218bb5e1a