172.dll

The module 172.dll has been detected as adware by 5 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Re-Markable’. This file is typically installed with the program Re-Markable by Revizer Technologies which is a potentially unwanted software program. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
Remove 172.dll - Powered by Reason Core Security
MD5:
a566d4ffeb24613f406a2f7b638eb8bb

SHA-1:
adc55d033b4f31d848c773d3567fa1f31854a5bc

SHA-256:
8a02d2c1e509835ccb2837e6da8a0e6650422338dea9cdfaa13c58ed0b28fc2c

Scanner detections:
5 / 68

Status:
Adware

Analysis date:
12/7/2016 7:42:53 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/Zbot.G
2015.0.3337

Dr.Web
Win32.Rmnet.8
9.0.1.0271

Microsoft Security Essentials
Threat.Undefined
1.183.359.0

Reason Heuristics
Adware.Revizer.BHO.D
14.8.13.22

VIPRE Antivirus
Threat.4732184
32210

Remove 172.dll - Powered by Reason Core Security
File size:
187 KB (191,488 bytes)

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\re-markable-soft\172.dll

File PE Metadata
Compilation timestamp:
6/8/2014 11:07:46 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:B/Ss1zfJM+qEXhTHtXNYdAC9DR+E8C6UJnDyfmtY8Temjg8g:VJ5q+TN5NkhqU1NtY8Tax

Entry address:
0xCB36

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 2A, 5E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 18, 14, 02, 10, E8, 5B, 3F, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 60, 4E, 02, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 68, B1, 01, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.4278

Developed / compiled with:
Microsoft Visual C++

Code size:
98 KB (100,352 bytes)

Internet Explorer BHO
Display name:
Re-Markable

CLSID:
{3D516515-DFE7-3019-459D-1600075B6EC6}


The file 172.dll has been discovered within the following program.

Re-Markable  by Revizer Technologies
Re-Markable is an advertising injecting web browser addon that displays ads on web pages not associated with the program. It does this by using a local proxy server to route all web traffic through and display ads in the forms of banner ads, video ads and text-links.
re-markable.net
80% remove it
 
Powered by Should I Remove It?

Remove 172.dll - Powered by Reason Core Security