{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w.sys

trolatunt

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w.sys by trolatunt has been detected as adware by 22 anti-malware scanners. It runs as a Windows kernel mode device driver named “{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
StdLib  (signed by trolatunt)

Product:
StdLib

Version:
1.4.3.1 built by: WinDDK

MD5:
4e6006fb87d247f49f2f5a1cf3bcb2e8

SHA-1:
775d99d7957ac3dadad2cc4b9c7bb80c6c4c3982

SHA-256:
c7b49457ee3ba66b3c6848080300d0c32dddd260080e41219935a61f5721cffb

Scanner detections:
22 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/24/2024 12:00:16 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.N
826

Agnitum Outpost
Trojan.BPlug
7.1.1

Avira AntiVirus
Adware/BrowseFox.A.197
7.11.174.222

avast!
Win32:Truntalol-C [PUP]
2014.9-141101

AVG
Trolatunt
2015.0.3304

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14111

Bitdefender
Adware.SwiftBrowse.N
1.0.20.1525

Dr.Web
Trojan.BPlug.123
9.0.1.0305

Emsisoft Anti-Malware
Adware.SwiftBrowse.N
8.14.11.01.08

F-Secure
Adware.SwiftBrowse.N
11.2014-01-11_7

G Data
Adware.SwiftBrowse
14.11.24

IKARUS anti.virus
AdWare.SwiftBrowse
t3scan.1.7.8.0

McAfee
Artemis!8F3AB16750F5
5600.6960

MicroWorld eScan
Adware.SwiftBrowse.N
15.0.0.915

NANO AntiVirus
Riskware.Win32.Yotoon.ddghtt
0.28.2.61721

nProtect
Adware.SwiftBrowse.N
14.05.30.01

Reason Heuristics
PUP.trolatunt.k
14.11.1.8

Sophos
OutoBox
4.98

Trend Micro House Call
TROJ_GEN.F47V0529
7.2.305

Vba32 AntiVirus
AdWare.Win64.Yotoon
3.12.26.3

VIPRE Antivirus
Yontoo
33200

Zillya! Antivirus
Adware.Yotoon.Win64.7
2.0.0.1926

File size:
51.2 KB (52,408 bytes)

Product version:
1.4.3.1

Copyright:
Copyright © 2013 StdLib

Original file name:
StdLib.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/20/2013 9:00:00 PM

Valid to:
8/20/2015 8:59:59 PM

Subject:
CN=trolatunt, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=trolatunt, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
16E5B55BC9746E627E43F6A38DDE3E80

File PE Metadata
Compilation timestamp:
8/6/2014 8:52:14 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:ZIsHpnKnCBSqUPJHKQpkJvRpvqIT2bcWiJmOt13g2rp3lnCH:2sHRKnLJqQpkIITsiTt1xt2

Entry address:
0xC03E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 62, 50, FF, FF, CC, CC, 74, C1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BC, C4, 00, 00, C0, A0, 00, 00, B4, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 12, C5, 00, 00, 00, A0, 00, 00, EC, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, AE, C8, 00, 00, 38, A0, 00, 00, C4, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A6, C9, 00, 00, 10, A0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, EA, C4, 00, 00, FE, C4, 00, 00, D6, C4...
 
[+]

Code size:
37 KB (37,888 bytes)

Driver
Display name:
{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}w.sys - Powered by Reason Core Security