boxrock.ieupdate.dll

Box Rock

This is the Internet Explorer add-on for the Yontoo Box Rock branded web browser plugin (injects banner, text-link and popup ads). The component is responisble for registering the Browser Helper Object into IE and keeping it registered. The module boxrock.ieupdate.dll by Box Rock has been detected as adware by 21 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Box Rock  (signed and verified)

Version:
1.0.5504.22887

MD5:
8a367b86bb46f5a391cbbe823668d103

SHA-1:
e4c8284e1ad9655e0bc064e9329eb5e52b236812

SHA-256:
f3f69bb9e13d0c5a1fa6c2016434a6c3310792ec8460dd3d2bc605363694c49e

Scanner detections:
21 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser add-on for Internet Explorer.

Analysis date:
4/25/2024 2:25:58 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.AT
6475091

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.205.178

avast!
Win32:BrowseFox-EZ [PUP]
150126-0

AVG
Generic
2016.0.3215

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.15128

Bitdefender
Adware.BrowseFox.AT
1.0.20.140

Emsisoft Anti-Malware
Adware.BrowseFox.AT
9.0.0.4799

ESET NOD32
MSIL/BrowseFox.L potentially unwanted application
7.0.302.0

F-Secure
Adware.BrowseFox.AT
5.13.68

G Data
Adware.BrowseFox.AT
15.1.25

IKARUS anti.virus
PUA.MSIL.BrowseFox
t3scan.1.8.6.0

K7 AntiVirus
Adware
13.193.14786

McAfee
BrowseFox-FUT
5600.6871

MicroWorld eScan
Adware.BrowseFox.AT
16.0.0.84

nProtect
Adware.BrowseFox.AT
15.01.28.01

Panda Antivirus
Trj/CI.A
15.01.28.12

Qihoo 360 Security
Win32/Virus.Adware.708
1.0.0.1015

Reason Heuristics
Adware.Yontoo.BoxRock
15.1.28.12

Sophos
Generic PUA OE
4.98

Trend Micro House Call
ADW_BROWFOX
7.2.28

Trend Micro
ADW_BROWFOX
10.465.28

File size:
657.2 KB (673,000 bytes)

Product version:
1.0.5504.22887

Original file name:
BoxRock.IEUpdate2015012620.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\box rock\bin\plugins\boxrock.ieupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/7/2014 1:00:00 AM

Valid to:
10/3/2015 12:59:59 AM

Subject:
CN=Box Rock, O=Box Rock, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1125198B1C5DF8CC1185255178F1DAFC

File PE Metadata
Compilation timestamp:
1/26/2015 8:42:58 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:UxzBxXuUkV+ho0G+kMD3aEO3REMJeEdhRXuu3XRBvHO8hprubNTIXqa3MM5sYC:sfeNYo0G+rDbOmM/hRXuu3XHvz0OMz

Entry address:
0xA4352

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.8210

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
649 KB (664,576 bytes)

Remove boxrock.ieupdate.dll - Powered by Reason Core Security