{4df60d2c-927b-478c-83f0-b7dc923bae60}.dll

XVRNT

Yula

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module {4df60d2c-927b-478c-83f0-b7dc923bae60}.dll, “TODO: <File description>” by Yula has been detected as adware by 24 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
TODO: <Company name>  (signed by Yula)

Product:
XVRNT

Description:
TODO: <File description>

Version:
3.1.0.3

MD5:
63abfafe832231c126daf9e37e2216df

SHA-1:
b0a2694b01887beaa7cff3afff193132e6fa2d0a

SHA-256:
ed92d9e69636a50273863ff98445441b36e9e3579910dfec2b5c552757dbab51

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/18/2024 3:05:13 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.D
890

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.Agent
2014.08.30

Avira AntiVirus
APPL/BrowseFox.Gen
7.11.169.248

avast!
Win32:BrowseFox-C [PUP]
140813-1

AVG
Zula
2015.0.3368

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14829

Bitdefender
Adware.BrowseFox.D
1.0.20.1205

Clam AntiVirus
Win.Adware.Swiftbrowse-20
0.98/19280

Dr.Web
Trojan.BPlug.100
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox
8.14.08.29.10

ESET NOD32
Win32/BrowseFox.M potentially unwanted application
7.0.302.0

F-Prot
W32/MegaBrowse.A
v6.4.6.5.141

F-Secure
Adware.BrowseFox.D
11.2014-29-08_6

G Data
Adware.BrowseFox
14.8.24

IKARUS anti.virus
AdWare.SwiftBrowse
t3scan.1.6.1.0

Kaspersky
not-a-virus:AdWare.Win32.Kranet
14.0.0.3333

MicroWorld eScan
Adware.BrowseFox.D
15.0.0.723

NANO AntiVirus
Trojan.Win32.BPlug.decyqf
0.28.2.61861

nProtect
Adware.BrowseFox.D
14.07.25.01

Reason Heuristics
PUP.Yula.g
14.8.29.10

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Threat.4150696
29708

Zillya! Antivirus
Adware.SwiftBrowse.Win32.7
2.0.0.1845

File size:
274.3 KB (280,856 bytes)

Product version:
3.1.0.3

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
XTLS.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\yula\bin\{4df60d2c-927b-478c-83f0-b7dc923bae60}.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/15/2014 1:00:00 AM

Valid to:
3/16/2015 12:59:59 AM

Subject:
CN=Yula, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Yula, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4B2C13D47B877663487D003C021E7110

Registration
CLSID:
{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}

COM registered:
Yes

File PE Metadata
Compilation timestamp:
7/24/2014 11:02:23 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:BBonp3IPdpolpcswvERohKpsoY+aga5iMJPfjryOAZ3SijQlZyh1eTnNyX9nS75r:BmnJIvoTjyl5VffJALQl0hAcnIBDUc

Entry address:
0x1F6A7

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, A0, 7E, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, B8, 9C, 80, 02, 10, A3, 98, F2, 03, 10, C7, 05, 9C, F2, 03, 10, 92, 77, 02, 10, C7, 05, A0, F2, 03, 10, 46, 77, 02, 10, C7, 05, A4, F2, 03, 10, 7F, 77, 02, 10, C7, 05, A8, F2, 03, 10, E8, 76, 02, 10, A3, AC, F2, 03, 10, C7, 05, B0, F2, 03, 10, 14, 80, 02, 10, C7, 05, B4, F2, 03, 10, 04, 77, 02, 10, C7, 05, B8, F2, 03, 10, 66, 76, 02, 10, C7, 05, BC, F2, 03, 10, F2, 75...
 
[+]

Code size:
192.5 KB (197,120 bytes)

Remove {4df60d2c-927b-478c-83f0-b7dc923bae60}.dll - Powered by Reason Core Security