{46183ba5-b8ed-40db-be57-6d0aafedc715}gw64.sys

ViewPlay

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {46183ba5-b8ed-40db-be57-6d0aafedc715}gw64.sys by ViewPlay has been detected as adware by 28 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “{46183ba5-b8ed-40db-be57-6d0aafedc715}Gw64”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
StdLib  (signed by ViewPlay)

Product:
StdLib

Version:
1.4.3.1 built by: WinDDK

MD5:
c50f2bcd3a9c6af2487566e480895b30

SHA-1:
b9aed37962d792f41f336425b8875184c7573999

SHA-256:
352d99a6665394e74fe1845e223b47cecbf09a51beb12c152785ff050b41e148

Scanner detections:
28 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 3:32:26 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.CH
366

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Trojan/Win64.SwiftBrowse
2014.08.28

avast!
MSIL:BrowseFox-CB [PUP]
2014.9-160204

AVG
Generic
2017.0.2844

Bitdefender
Adware.SwiftBrowse.CH
1.0.20.175

Bkav FE
W64.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Swiftbrowse-497
0.98/21511

Dr.Web
Trojan.Yontoo.1823
9.0.1.035

Emsisoft Anti-Malware
Adware.SwiftBrowse.CH
8.16.02.04.09

ESET NOD32
Win64/BrowseFox.BJ (variant)
10.10655

Fortinet FortiGate
Adware/BrowseFox
2/4/2016

F-Prot
W64/A-59c9c70a
v6.4.7.1.166

F-Secure
Adware.SwiftBrowse.CH
11.2016-04-02_5

G Data
Adware.SwiftBrowse.CH
16.2.25

IKARUS anti.virus
AdWare.SpadeCast
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.202.15424

McAfee
Artemis!B977E8EC52C1
5600.6500

MicroWorld eScan
Adware.SwiftBrowse.CH
17.0.0.105

Norman
Adware.SwiftBrowse.CH
11.20160204

nProtect
Adware.SwiftBrowse.CH
15.03.30.01

Reason Heuristics
PUP.Yontoo.ViewPlay (M)
16.2.4.9

Sophos
BrowseSmart
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
9344

Trend Micro House Call
HS_BROWSEFOX.SM
7.2.35

Trend Micro
HS_BROWSEFOX.SM
10.465.04

VIPRE Antivirus
Trojan.Win32.Generic
38900

Zillya! Antivirus
Adware.Yotoon.Win64.14
2.0.0.2121

File size:
59.7 KB (61,112 bytes)

Product version:
1.4.3.1

Copyright:
Copyright © 2013 StdLib

Original file name:
StdLib.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\{46183ba5-b8ed-40db-be57-6d0aafedc715}gw64.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/26/2013 7:00:00 PM

Valid to:
11/27/2014 6:59:59 PM

Subject:
CN=ViewPlay, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ViewPlay, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0F9F45EC13C318E3C0F42DA156EA0A92

File PE Metadata
Compilation timestamp:
8/6/2014 7:52:18 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:Got2dxF9O8ZF33iqiIy9387Hp9XcfBzSowidIm5M:G9JRicy938Lp9eW1j8M

Entry address:
0xF064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 2E, 20, FF, FF, CC, CC, 38, F2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 1C, F6, 00, 00, 60, C1, 00, 00, 28, F1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BE, F9, 00, 00, 50, C0, 00, 00, D8, F0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, FA, 00, 00, 00, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 9A, FA, 00, 00, 00, 00, 00, 00, 86, FA, 00, 00...
 
[+]

Entropy:
5.9516

Code size:
46.5 KB (47,616 bytes)

Driver
Display name:
{46183ba5-b8ed-40db-be57-6d0aafedc715}Gw64

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI