buzz-itgay158.dll

The module buzz-itgay158.dll has been detected as adware by 9 anti-malware scanners. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
716cbb27e05e9b336462cf0bc49b57b6

SHA-1:
45c5080c8f54094ba78d42469c61b2f3e262b649

SHA-256:
eff679467abbdab9dd2a337cdc75603f5eb31a1597cfde519a5f6ef3f183da50

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
4/25/2024 6:51:49 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Dropper-gen [Drp]
140813-1

AVG
Adware Generic5.BDEW
2014.0.4015

Dr.Web
Trojan.Revizer.24
9.0.1.05190

ESET NOD32
Win32/AdWare.AddLyrics.BA application
7.0.302.0

McAfee
PUP-FJD
5600.7024

NANO AntiVirus
Trojan.Win32.Revizer.cxcxla
0.28.2.61861

Qihoo 360 Security
Win32/Trojan.Dropper.c9f
1.0.0.1015

Reason Heuristics
Adware.Revizer.N
14.8.28.22

VIPRE Antivirus
Threat.5063086
32210

File size:
130 KB (133,120 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\buzz-it-soft\buzz-itgay158.dll

File PE Metadata
Compilation timestamp:
4/16/2014 12:27:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:rBYpPbVHjgnl1vTxdVVnBntTXwb3c9fme1uT73WTBfWPyrw:rBCVDml9pV5Kzk+eIXWTB+6

Entry address:
0xD12F

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, BC, 56, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 50, 01, 02, 10, 89, 0D, 4C, 01, 02, 10, 89, 15, 48, 01, 02, 10, 89, 1D, 44, 01, 02, 10, 89, 35, 40, 01, 02, 10, 89, 3D, 3C, 01, 02, 10, 66, 8C, 15, 68, 01, 02, 10, 66, 8C, 0D, 5C, 01, 02, 10, 66, 8C, 1D, 38, 01, 02, 10, 66, 8C, 05, 34, 01, 02, 10, 66, 8C, 25, 30, 01, 02, 10, 66, 8C, 2D, 2C, 01, 02, 10, 9C, 8F, 05, 60, 01...
 
[+]

Entropy:
6.5375

Code size:
89 KB (91,136 bytes)

Remove buzz-itgay158.dll - Powered by Reason Core Security