51d6ab57418a43179cb9.dll

Lampy Lighty

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module 51d6ab57418a43179cb9.dll by Lampy Lighty has been detected as adware by 24 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Lampy Lighty  (signed and verified)

MD5:
77324a794f50a4d2963271dbad4b3e53

SHA-1:
aca4ef45e2c7e23a0f7a22dfeb0bde7c2622555c

SHA-256:
ad4283c42690d74a69644d68d6500bbadbe689c679c55406b00830f4b8855539

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 6:40:17 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MPlug.Q
836

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.180.144

AVG
Generic
2015.0.3314

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.141022

Bitdefender
Adware.MPlug.Q
1.0.20.1475

Clam AntiVirus
Win.Adware.Swiftbrowse-546
0.98/21411

Dr.Web
Trojan.BPlug.301
9.0.1.05190

Emsisoft Anti-Malware
Adware.MPlug.Q
8.14.10.22.08

ESET NOD32
probably Win32/BrowseFox.N potentially unwanted application
7.0.302.0

F-Secure
Adware.MPlug.Q
11.2014-22-10_4

G Data
Adware.MPlug
14.10.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

McAfee
Artemis!BBA0B0012B3D
5600.6970

MicroWorld eScan
Adware.MPlug.Q
15.0.0.885

NANO AntiVirus
Riskware.Win32.Kranet.dgstaw
0.28.2.62841

nProtect
Adware.MPlug.Q
14.08.19.01

Reason Heuristics
PUP.LampyLighty.U
14.11.1.12

Sophos
Browse Fox
4.98

Trend Micro House Call
ADW_BROWSEF
7.2.295

Trend Micro
ADW_BROWSEF
10.465.22

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Yontoo
32378

Zillya! Antivirus
Adware.Kranet.Win32.76
2.0.0.1899

File size:
190.2 KB (194,808 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\lampy lighty\bin\51d6ab57418a43179cb9.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/5/2014 1:00:00 AM

Valid to:
8/6/2015 12:59:59 AM

Subject:
CN=Lampy Lighty, O=Lampy Lighty, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7781DD1C520C847A823706BB0C57BEB8

File PE Metadata
Compilation timestamp:
10/13/2014 12:32:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:SP37RBT2symmM3xx0y9dH0Xhk7IQ0Li41iTzYG5vVkc7qzX9PfDqds5bK:SPLjrX9dH0Xhe8i41EzYGNVVGz9nDas4

Entry address:
0x11BED

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 81, 7C, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, D0, 45, 02, 10, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 34, 40, 02, 10, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64...
 
[+]

Entropy:
6.5606

Code size:
139.5 KB (142,848 bytes)

Remove 51d6ab57418a43179cb9.dll - Powered by Reason Core Security