What is Feven?

Feven is software application developed by Crossrider Advanced Technologies Ltd. (Platform). It is most commonly found on computers running Windows 7 with nearly 66.67% of installations running this operating system. Feven's installer is typically 8.00 MB in size and installs around 44 files. The most common release is 1.33.153.1 with 35.74% of all installations currently using this version.

Feven is most popular in the United States with 25.88% of installations residing in this country.

Feven adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About Feven?

Feven is a powerful web browser extension designed to enhance the browsing experience by modifying the search and home pages. It also incorporates features to protect the default browser search engine while generating search advertising revenue. Typically distributed through bundled offers within third-party software, Feven seamlessly integrates into the browser to offer the following functionalities: - Modifying the default search engine, including the browser's built-in search box, and address bar. - Altering the default Home Page and/or New Tabs while safeguarding your search settings. - Adding alternative error page functionality, like "Page Not Found". With Feven, users can customize their browsing preferences while benefitting from an enhanced and streamlined search experience.

Multiple virus scanners have detected malware in Feven.

utils.exe (MD5: dd0a810d4abf6942dcc15cab68d1b21f) has been flagged by 40 scanners:
Scanner Software Result
Bkav FE HW32.CDB
Malwarebytes PUP.Optional.Feven.A
Symantec WS.Reputation
Lavasoft Ad-Aware Adware.Generic.929234
AegisLab W32.Sality
Agnitum Outpost PUA.Toolbar.CrossRider!
avast! Win32:Crossrider-AI [PUP]
AVG Generic5.ANCK
Avira Adware/CrossRider.A.10284
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.T
Bitdefender Adware.Generic.929234
CAT-QuickHeal AdWare.Feven.r5 (Not a Virus)
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.950
Emsisoft Anti-Malware Adware.Generic.929234 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.T
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-f837d5f1!Eldorado
F-Secure Adware.Generic.929234
G Data Adware.Generic.929234
K7 AntiVirus Trojan ( 00494ca01 )
K7GW Trojan ( 00494ca01 )
McAfee Adware-AddLyrics
McAfee-GW-Edition BehavesLike.Win32.AdwareCross.hh
Microsoft Security Essentials Adware:Win32/Feven
MicroWorld-eScan Adware.Generic.929234
NANO AntiVirus Trojan.Win32.Crossrider.cvxsxs
Qihoo-360 Win32/Virus.Adware.d90
Sophos AppRider
Trend Micro TROJ_GEN.R0CBC0CCH14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Lyckriks.Win32.571
Clam AntiVirus Win.Adware.Plush-29
Jiangmin AdWare/Lyckriks.ki
TrendMicro-HouseCall TROJ_GEN.R0CBC0CCH14
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Lyckriks
Kingsoft AntiVirus Win32.Troj.Lyckriks.mk.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Panda Antivirus Trj/CI.A
Feven 1.7-updater.exe (MD5: ddd109d17ff832503060b9a7c2c6ea05) has been flagged by 3 scanners:
Scanner Software Result
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.K
Malwarebytes PUP.Optional.Feven.A
VIPRE Antivirus Crossrider (fs)
Feven 1.7-firefoxinstaller.exe (MD5: f23cbb54a7a79f5f5d522a7948754726) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.2u1@mKdf!qpO
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.Addlyrics
avast! Win32:Crossrider-AI [PUP]
AVG Toolbar.UD
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.2u1@mKdf!qpO
Bkav FE W32.HfsAdware.A7F9
Comodo Security ApplicUnwnt
Cyren W32/A-6583813c!Eldorado
Dr.Web Trojan.Crossrider1.23864
ESET-NOD32 Win32/Toolbar.CrossRider.S potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-6583813c!Eldorado
F-Secure Gen:Application.Heur.2u1@mKdf!qpO
G Data Gen:Application.Heur.2u1@mKdf!qpO
Malwarebytes PUP.Optional.Feven.A
McAfee Adware-AddLyrics
McAfee-GW-Edition Adware-AddLyrics
MicroWorld-eScan Gen:Application.Heur.2u1@mKdf!qpO
NANO AntiVirus Riskware.Win32.Toolbar.czjdfd
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R0C1C0EJB14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJB14
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CroRi.Win32.137
Jiangmin AdWare/Lyckriks.cu
K7 AntiVirus Riskware
K7GW Riskware
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks
Feven 1.7-enabler.exe (MD5: 8e1cc90006c32a0ed9cd72b3eed7950a) has been flagged by 42 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.vu1@mS@yIabO
Agnitum Outpost PUA.Agent!
AhnLab-V3 PUP/Win32.Addlyrics
Arcabit Application.Heur.EA19E9
avast! Win32:IeEnablerC-G [Adw]
AVG Generic5.ANHA
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.45
Bitdefender Gen:Application.Heur.vu1@mS@yIabO
Bkav FE W32.HfsAdware.A7F9
CAT-QuickHeal PUA.Feven.A6
Clam AntiVirus Win.Adware.Plush-29
Comodo Security ApplicUnwnt
Cyren W32/S-a64d6097!Eldorado
Dr.Web Trojan.Crossrider1.23864
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.T potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/S-a64d6097!Eldorado
F-Secure Gen:Application.Heur.vu1@mS@yIabO
G Data Gen:Application.Heur.vu1@mS@yIabO
IKARUS anti.virus AdWare.CrossRider
Jiangmin AdWare/Lyckriks.ki
K7 AntiVirus Adware ( 004bbf581 )
K7GW Adware ( 004bbf581 )
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.Feven.A
McAfee Adware-AddLyrics
McAfee-GW-Edition Adware-AddLyrics
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
MicroWorld-eScan Gen:Application.Heur.vu1@mS@yIabO
NANO AntiVirus Trojan.Win32.Toolbar.ctsoci
Rising Antivirus PE:Malware.Adload!6.1D39
Sophos AppRider (PUA)
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R047C0EFG15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.Agent.Win32.9493
TrendMicro-HouseCall TROJ_GEN.R0CBC0EBJ15
Vba32 AntiVirus AdWare.Lyckriks
Feven 1.7-codedownloader.exe (MD5: 734a9de172e84812b5dcd91929209a32) has been flagged by 39 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Gu1@mS2ECkmO
Agnitum Outpost PUA.Agent!
AhnLab-V3 PUP/Win32.Addlyrics
Arcabit Application.Heur.E8AAAA
avast! Win32:Crossrider-AI [PUP]
AVG Crossrider.OF
Avira ADWARE/CrossRider.Gen2
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.Gu1@mS2ECkmO
CAT-QuickHeal PUA.Feven.A6
Comodo Security ApplicUnwnt
Cyren W32/A-eb9ef301!Eldorado
Dr.Web Trojan.Crossrider1.23864
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.T potentially unwanted
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
F-Secure Gen:Application.Heur.Gu1@mS2ECkmO
G Data Gen:Application.Heur.Gu1@mS2ECkmO
IKARUS anti.virus AdWare.CrossRider
Jiangmin Adware/Agent.apqp
K7 AntiVirus Trojan ( 004a08ef1 )
K7GW Trojan ( 004a08ef1 )
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
McAfee Adware-AddLyrics
McAfee-GW-Edition Adware-AddLyrics
Microsoft Security Essentials Adware:Win32/Feven
MicroWorld-eScan Gen:Application.Heur.Gu1@mS2ECkmO
NANO AntiVirus Riskware.Win32.Downware.cynnrj
Sophos AppRider
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Trend Micro TROJ_GEN.R047C0CFG15
VIPRE Antivirus Crossrider (fs)
Zillya Backdoor.PePatch.Win32.37980
Bkav FE W32.HfsAdware.A7F9
Malwarebytes PUP.Optional.Feven.A
TrendMicro-HouseCall TROJ_GEN.R0CBC0EBJ15
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Vba32 AntiVirus AdWare.Lyckriks

Software Behaviors

Scheduled tasks:
  • Feven 1.7-firefoxinstaller.exe is scheduled as a task named 'Feven 1.7-firefoxinstaller'.

Startup Entries

Startup tasks:
  • Feven 1.5-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.5-firefoxinstaller.
  • Feven 1.5-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.5-chromeinstaller.
  • Feven 1.5-updater.exe is automatically launched at startup through a scheduled task named Feven 1.5-updater.
  • Feven 1.5-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.5-enabler.
  • Feven 1.5-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.5-codedownloader.
  • Feven 1.7-updater.exe is automatically launched at startup through a scheduled task named Feven 1.7-updater.
  • Feven 1.7-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.7-enabler.
  • Feven 1.7-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.7-codedownloader.
  • Feven 1.7-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.7-firefoxinstaller.
  • Feven 1.7-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.7-chromeinstaller.
  • Feven 1.8-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.8-enabler.
  • Feven 1.8-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.8-chromeinstaller.
  • Feven 1.8-validator.exe is automatically launched at startup through a scheduled task named Feven 1.8-validator.
  • Feven 1.8-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.8-codedownloader.

Software Details

URL:
https://crossrider.com/pages/extension_eula
Support:
–
Installation path:
C:\Program Files\Feven 1.8
Uninstaller:
C:\Program Files\Feven 1.8\Uninstall.exe /fromcontrolpanel=1
Size:
8.00 MB
Language:
English

Feven Executable Details

Primary executable:
utils.exe
Name:
Feven
Path:
C:\Program Files\Feven 1.8\utils.exe
MD5:
dd0a810d4abf6942dcc15cab68d1b21f
SHA-1:
–
SHA-256:
–
Files installed by Feven
File Type Filename MD5
EXE
ca87304ae3d45272dbc1747c29782748
EXE
8d2a3041ce3c03d2c888ecc96ec73ecd
DLL
3df3e703b6f78c1cd2e1c4fd5f71946c
DLL
355aa1ff3f6d918840a37a782bc7f99a
EXE
a561646afa646e5a12b85a62e929b2c7
EXE
20f8da81f81e4b3e93413a5d4d5846b6
DLL
c99d5a8ebfc5fbb8885b7a7e3ce479e5
DLL
5ae9576fc4c35e3390e4ede645bf1f10
EXE
eb238175914a265a55916593aaec1f9c
EXE
1fb776f1dbafdace4b7bbb4e375aea0f