bkyliylzxar.dll

Acute Angle Solutions Ltd.

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The module bkyliylzxar.dll by Acute Angle Solutions has been detected as adware by 16 anti-malware scanners.
Publisher:
Acute Angle Solutions Ltd.  (signed and verified)

MD5:
671ae10fd0d5144f2da37ef8a7eb25fe

SHA-1:
f2ed15581993e5d5aee2244cb82f1ff176ec1933

SHA-256:
b5c296a818e7e05fa59c0b5d72e04e48d9ae5d1581c64ef8f34f0552f99d4b39

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/24/2024 8:39:48 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.PullUpdate.B
868

Avira AntiVirus
ADWARE/Adware.Gen
7.11.174.78

AVG
Acute
2015.0.3275

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.14919

Bitdefender
Adware.PullUpdate.B
1.0.20.1310

Emsisoft Anti-Malware
Adware.PullUpdate
8.14.09.19.07

ESET NOD32
MSIL/Adware.PullUpdate.C application
8.7.0.302.0

F-Secure
Adware.PullUpdate.B
11.2014-19-09_6

G Data
Adware.PullUpdate
14.9.24

herdProtect (fuzzy)
2014.11.30.6

K7 AntiVirus
Adware
13.183.13476

MicroWorld eScan
Adware.PullUpdate.B
15.0.0.786

nProtect
Adware.PullUpdate.B
14.09.24.01

Reason Heuristics
PUP.AcuteAngleSolutions.L
14.9.19.19

Sophos
Pull Update
4.98

VIPRE Antivirus
Threat.4784449
32938

File size:
1.1 MB (1,186,176 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\ProgramData\gkdkltl\dat\bkyliylzxar.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/30/2014 10:00:00 PM

Valid to:
1/31/2015 9:59:59 PM

Subject:
CN=Acute Angle Solutions Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Acute Angle Solutions Ltd., L=St. James, S=St. James, C=BB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0A7A77148C6F7A33F9174DA187F6FEF0

File PE Metadata
Compilation timestamp:
9/11/2014 9:27:38 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:qG1H5zeCK19B2G8i5UvGuoe5vLBpWMD6xZjzMHos/xU3TY:R5W1CniOvEMD6xNg/CT

Entry address:
0xB0C74

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 42, C1, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 34, 91, 11, 45, 00, 74, 05, E9, 95, C1, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03...
 
[+]

Code size:
820.5 KB (840,192 bytes)

Remove bkyliylzxar.dll - Powered by Reason Core Security