{552199fb-9890-4055-9aaf-b2f6d51d46e9}64.dll

XVRNT

PlurPush

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module {552199fb-9890-4055-9aaf-b2f6d51d46e9}64.dll, “TODO: <File description>” by PlurPush has been detected as adware by 29 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
TODO: <Company name>  (signed by PlurPush)

Product:
XVRNT

Description:
TODO: <File description>

Version:
3.1.0.4

MD5:
e1fef78767d004a94f876bf83a325c66

SHA-1:
f7bd251099c46fbd119cdbe2b9e5d6f726656c85

SHA-256:
f22f5bf3368e084a0d1c58396fc8058ff6ea3195e7491d0813f45f33f0bc8b80

Scanner detections:
29 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/27/2024 12:41:28 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BO
358

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
Win-PUP/BrowseFox.Gen
2015.02.09

Avira AntiVirus
ADWARE/BrowseFox.Gen
7.11.208.204

avast!
Win32:BrowseFox-DX [PUP]
2014.9-160212

AVG
Generic_r
2017.0.2836

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.16212

Bitdefender
Adware.BrowseFox.BO
1.0.20.215

Clam AntiVirus
Win.Adware.Swiftbrowse-732
0.98/20114

Dr.Web
Trojan.Yontoo.115
9.0.1.043

Emsisoft Anti-Malware
Adware.BrowseFox.BO
8.16.02.12.11

ESET NOD32
Win64/BrowseFox.CK potentially unwanted application
10.7.0.302.0

Fortinet FortiGate
Adware/BrowseFox
2/12/2016

F-Prot
W64/S-6dc29f50
v6.4.7.1.166

F-Secure
Adware.BrowseFox.BO
11.2016-12-02_6

G Data
Adware.BrowseFox.BO
16.2.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.8.0

K7 AntiVirus
Adware
13.193.14899

McAfee
Program.BrowseFox.e
5600.6492

MicroWorld eScan
Adware.BrowseFox.BO
17.0.0.129

nProtect
Adware.BrowseFox.BO
15.02.06.01

Panda Antivirus
Generic Suspicious
16.02.12.11

Quick Heal
Adware.Yotoon.A7
2.16.14.00

Reason Heuristics
PUP.Yontoo.PlurPush (M)
16.2.12.11

SUPERAntiSpyware
Adware.BrowseFox/Variant
9328

Trend Micro House Call
TROJ_GEN.R0C1C0OA315
7.2.43

Trend Micro
TROJ_GEN.R0C1C0OA315
10.465.12

VIPRE Antivirus
Yontoo
37370

Zillya! Antivirus
Adware.SwiftBrowse.Win64.1
2.0.0.2058

File size:
241.3 KB (247,064 bytes)

Product version:
3.1.0.4

Copyright:
TODO: (c) <Company name>. All rights reserved.

Original file name:
XTLS.dll

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\plurpush\bin\{552199fb-9890-4055-9aaf-b2f6d51d46e9}64.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/19/2013 5:00:00 AM

Valid to:
9/20/2015 4:59:59 AM

Subject:
CN=PlurPush, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PlurPush, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
30ACE095C6EE9F3C39428EB86ECAFADF

File PE Metadata
Compilation timestamp:
8/14/2014 11:52:41 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:0T5ArblGreJAItMSjGy3PSTRdFDWobXD2RBRgCR:u5UlGrelMStE9a

Entry address:
0x187F0

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 2F, 60, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, 48, 8D, 05, 49, 62, 00, 00, 48, 8D, 0D, 92, 6D, 00, 00, 48, 89, 05, 63, EA, 01, 00, 48, 8D, 05, 24, 62, 00, 00, 48, 89, 0D, 4D, EA, 01, 00, 48, 89, 05, 56, EA, 01, 00, 48, 8D, 05, 17, 62, 00, 00, 48, 89, 0D, 60, EA, 01, 00, 48, 89, 05, 49, EA, 01, 00, 48...
 
[+]

Entropy:
6.0627

Code size:
149.5 KB (153,088 bytes)

Remove {552199fb-9890-4055-9aaf-b2f6d51d46e9}64.dll - Powered by Reason Core Security