ClearThink.IEUpdate.dll

ClearThink

This is the Internet Explorer add-on for the Yontoo ClearThink branded web browser plugin (injects banner, text-link and popup ads). The component is responisble for registering the Browser Helper Object into IE and keeping it registered. The module ClearThink.IEUpdate.dll by ClearThink has been detected as adware by 8 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
ClearThink  (signed and verified)

Version:
1.0.5357.10217

MD5:
1a744b75d442baf4fea48a650b7163e2

SHA-1:
a6d700ca5d7d99a3745c2aadfa7ce35bd7716ecb

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser add-on for Internet Explorer.

Analysis date:
4/26/2024 5:29:10 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3363

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1492

Dr.Web
Trojan.BPlug.202
9.0.1.0245

ESET NOD32
MSIL/BrowseFox (variant)
8.10350

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3311

McAfee
Artemis!1A744B75D442
5600.7019

Qihoo 360 Security
Win32/Virus.Adware.e4c
1.0.0.1015

Reason Heuristics
Adware.Yontoo.ClearThink.S
14.9.2.17

File size:
532.2 KB (545,008 bytes)

Product version:
1.0.5357.10217

Original file name:
ClearThink.IEUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Swedish (Sweden)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/5/2014 2:00:00 AM

Valid to:
8/6/2015 1:59:59 AM

Subject:
CN=ClearThink, O=ClearThink, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1200063ED04B1DA36F7FE204B3DD8617

File PE Metadata
Compilation timestamp:
9/1/2014 8:40:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Q9soVYxiYZ3Z+NWJkA2iFw2/659k3WsliMgTF3MP:QlVkbZp+8JkQbW9JF3MP

Entry address:
0x84FAE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 10, 00, 00, 00, 18, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 30, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
524 KB (536,576 bytes)

Remove ClearThink.IEUpdate.dll - Powered by Reason Core Security