acerace.dll

Ace Race

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module acerace.dll by Ace Race has been detected as adware by 32 anti-malware scanners. This file is typically installed with the program ace race by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from install-cdn.acerace.net and multiple other hosts.
Publisher:
Ace Race  (signed and verified)

Product:
ace race

Version:
1.0.0.6

MD5:
54a14d6fd78da0a0e2bb0c9867c9f7be

SHA-1:
9c5738272b492872470cc322221ea97764aeed14

SHA-256:
520d2f82a6310e637686407a9857942bf333a011c806fc243b98acaff37b9e8e

Scanner detections:
32 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
5/5/2024 1:22:38 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BB
742

Agnitum Outpost
PUA.Agent
7.1.1

AhnLab V3 Security
Win-PUP/BrowseFox.Gen
2015.01.24

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.204.218

AVG
BrowseFox.F
2016.0.3220

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15123

Bitdefender
Adware.BrowseFox.BB
1.0.20.115

Clam AntiVirus
Win.Adware.Browsefox-245
0.98/21511

Comodo Security
Application.Win32.BrowseFox.JM
20821

Dr.Web
Trojan.Yontoo.476
9.0.1.023

Emsisoft Anti-Malware
Adware.BrowseFox.BB
8.15.01.23.08

ESET NOD32
Win32/BrowseFox (variant)
9.11065

Fortinet FortiGate
Adware/Agent
1/23/2015

F-Prot
W32/S-7bed2e86
v6.4.7.1.166

F-Secure
Adware.BrowseFox.BB
11.2015-23-01_6

G Data
Adware.BrowseFox.BB
15.1.24

K7 AntiVirus
Trojan
13.192.14734

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.2596

Malwarebytes
PUP.Optional.AceRace.A
v2015.01.23.08

McAfee
Artemis!54A14D6FD78D
5600.6876

MicroWorld eScan
Adware.BrowseFox.BB
16.0.0.69

NANO AntiVirus
Riskware.Win32.SwiftBrowse.dlbdsd
0.30.0.64812

nProtect
Adware.BrowseFox.BB
15.01.23.01

Panda Antivirus
Trj/CI.A
15.01.23.08

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Yontoo
15.1.23.20

Sophos
Generic PUA JM
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
10097

Trend Micro House Call
Suspicious_GEN.F47V0807
7.2.23

Vba32 AntiVirus
AdWare.SwiftBrowse
3.12.26.3

VIPRE Antivirus
Yontoo
32026

Zillya! Antivirus
Adware.Agent.Win32.9402
2.0.0.1850

File size:
244.2 KB (250,096 bytes)

Product version:
1.0.0.6

Copyright:
(c) ace race. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\acerace.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/6/2014 5:00:00 PM

Valid to:
10/7/2015 4:59:59 PM

Subject:
CN=Ace Race, O=Ace Race, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47DF877938071D6194F321723076892E

File PE Metadata
Compilation timestamp:
1/22/2015 7:43:28 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:zdhoOtou61z4NmbXRAIieGJrPf9eAxjN+EIaIyn70s1xk:zFtou694kLRAXeG7Iegs1xk

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 70, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, C4, 77, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, FC, A4, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3571

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file acerace.dll has been discovered within the following programs.

ace race  by Yontoo Technology, Inc.
Ace Race is an ad-supported program that will display third-party advertisements in the form of coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links through means including but not limited to the content of any web page accessed, plug-ins, add-ons, or the browser itself.
acerace.net/support
86% remove it
 
Powered by Should I Remove It?

The file acerace.dll has been seen being distributed by the following 2 URLs.

Remove acerace.dll - Powered by Reason Core Security