171.dll

The library 171.dll has been detected as malware by 41 anti-virus scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘VeriBrowse’. This file is typically installed with the program VeriBrowse by Revizer Technologies which is a potentially unwanted software program. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
c89aa18297a093c0e122dfba2f03f231

SHA-1:
ba92e8cb487fd2ec5eba4cafe200e7604051b735

SHA-256:
5d7779e4ecbf1bab141e26cf7b83c7a0a9f1437ddea4f6851c902825b668deda

Scanner detections:
41 / 68

Status:
File is infected by a Virus

Explanation:
The file is infected by a polymorphic file infector virus.

Analysis date:
4/25/2024 12:20:45 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Ramnit.N
865

Agnitum Outpost
Win32.Nimnul.Gen.2
7.1.1

AhnLab V3 Security
Win32/Ramnit.G
2014.06.14

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

avast!
Win32:RmnDrp
2014.9-140922

AVG
Win32/Zbot.F
2015.0.3343

Baidu Antivirus
Virus.Win32.Nimnul.$a
4.0.3.14922

Bitdefender
Win32.Ramnit.N
1.0.20.1325

Bkav FE
W32.InjectAdwaredDwnA1.PE
1.3.0.4959

Clam AntiVirus
W32.Ramnit-1
0.98/19086

Comodo Security
Virus.Win32.Ramnit.K
18539

Dr.Web
Win32.Rmnet.12
9.0.1.0265

Emsisoft Anti-Malware
Win32.Ramnit.N
8.14.09.22.01

ESET NOD32
Win32/Ramnit.H virus
8.7.0.302.0

Fortinet FortiGate
W32/Ramnit.C
9/22/2014

F-Prot
W32/Ramnit.E
v6.4.6.5.141

F-Secure
Win32.Ramnit.N
11.2014-22-09_2

G Data
Win32.Ramnit
14.9.24

IKARUS anti.virus
Virus.Win32.Ramnit
t3scan.1.6.1.0

K7 AntiVirus
Virus
13.1712403

Kaspersky
Virus.Win32.Nimnul
14.0.0.3212

Malwarebytes
Virus.Ramnit
v2014.09.22.01

McAfee
W32/Ramnit.a
5600.6999

Microsoft Security Essentials
Threat.Undefined
1.175.2155.0

MicroWorld eScan
Win32.Ramnit.N
15.0.0.795

NANO AntiVirus
Virus.Win32.Nimnul.bqjjnb
0.28.0.60253

Norman
Ramnit.AS
11.20140922

nProtect
Virus/W32.SpyEye
14.06.13.01

Panda Antivirus
W32/Cosmu.E
14.09.22.01

Qihoo 360 Security
Virus.Win32.Ramnit.A
1.0.0.1015

Quick Heal
W32.Ramnit.A
9.14.14.00

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.12

Rising Antivirus
PE:Win32.Mgr.b!1594784
23.00.65.14920

Sophos
W32/Ramnit-A
4.98

Total Defense
Win32/Ramnit.C
37.0.10997

Trend Micro House Call
PE_RAMNIT.DEN
7.2.265

Trend Micro
PE_RAMNIT.DEN
10.465.22

Vba32 AntiVirus
Virus.Win32.Nimnul.b
3.12.26.0

VIPRE Antivirus
Threat.4732184
29708

ViRobot
Win32.Nimnul.A
2011.4.7.4223

Zillya! Antivirus
Virus.Nimnul.Win32.2
2.0.0.1823

File size:
185 KB (189,440 bytes)

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\veribrowse-soft\171.dll

File PE Metadata
Compilation timestamp:
5/26/2014 5:08:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:SRBDcNKYJT7l6bjAldUwRiPf0pR+sLCyHJpZTCfSpjnrVs8v8g:8dw9RPdUkKqzLpJr/x

Entry address:
0xCA99

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, B7, 5E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 68, 13, 02, 10, E8, E8, 3F, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 60, 4E, 02, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 68, B1, 01, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.4365

Developed / compiled with:
Microsoft Visual C++

Code size:
97.5 KB (99,840 bytes)

Internet Explorer BHO
Display name:
VeriBrowse

CLSID:
{26A42B3A-2362-C659-AFB5-C0610D84F600}


The file 171.dll has been discovered within the following program.

VeriBrowse  by Revizer Technologies
VeriBrowse is an web browser advertisement injection extension that is designed with the core purpose of delivering ads to the user's web browser. Ads are in the form of banners (both static and videos) as well as context-hyper links.
81% remove it
 
Powered by Should I Remove It?

Remove 171.dll - Powered by Reason Core Security