ClearThink.BrowserFilterG.dll

ClearThink

Installed as part of the Yontoo ClearThink branded web browser extension, the BrowserFilter component is responsible for injecting advertising in the browser based on the context of the HTML being rendered. Ads are injected in the browser in the form of inline text, coupons, multi-site searching and additional offers. The module ClearThink.BrowserFilterG.dll by ClearThink has been detected as adware by 10 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
ClearThink  (signed and verified)

Version:
1.0.5377.11578

MD5:
153385721ce3b74420516427595ea63c

SHA-1:
3e19d03118026abed68151cc14f83b6b4f900665

SHA-256:
b18605096a8f46ab7eb9ae5696ba52771e9c34ed01bd4fae3184cd9921b964a3

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/19/2024 1:31:53 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.173.208

AVG
Generic
2015.0.3344

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.14922

ESET NOD32
MSIL/BrowseFox.G potentially unwanted application
7.0.302.0

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3213

McAfee
BrowseFox
5600.7000

Qihoo 360 Security
Win32/Virus.Adware.708
1.0.0.1015

Reason Heuristics
PUP.ClearThink.Y
14.9.22.10

Sophos
Browse Fox
4.98

VIPRE Antivirus
Threat.4741131
33120

File size:
313.2 KB (320,752 bytes)

Product version:
1.0.5377.11578

Original file name:
ClearThink.BrowserFilterG.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\clearthink\bin\plugins\clearthink.browserfilterg.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/5/2014 2:00:00 AM

Valid to:
8/6/2015 1:59:59 AM

Subject:
CN=ClearThink, O=ClearThink, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1200063ED04B1DA36F7FE204B3DD8617

File PE Metadata
Compilation timestamp:
9/21/2014 9:26:05 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:j+27ae5+Xgw5LdFWm7oJsceY/QCb3E03sU9VrBJZyawwnmZzSKz:jZee5kgATqh5/QUFjB8awqm1SKz

Entry address:
0x4E332

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
305 KB (312,320 bytes)

Remove ClearThink.BrowserFilterG.dll - Powered by Reason Core Security