ClearThinkBrowserFilter.exe

ClearThink

Installed as part of the Yontoo ClearThink branded web browser extension, the BrowserFilter component is responsible for injecting advertising in the browser based on the context of the HTML being rendered. Ads are injected in the browser in the form of inline text, coupons, multi-site searching and additional offers. The application ClearThinkBrowserFilter.exe by ClearThink has been detected as adware by 7 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
ClearThink  (signed and verified)

Version:
0.0.0.0

MD5:
9fc6f55b8b4d886581d3a0521a2f6aa0

SHA-1:
ea2096b39b198bda8b7a9c817ef93ef2ecf37607

SHA-256:
e48ae32fe511ae22f939e1c56e06224b3cfd2f9e5fc6d3b7a325dfbb64f51619

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/25/2024 7:43:45 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.173.24

AVG
Generic
2015.0.3346

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.14919

ESET NOD32
MSIL/BrowseFox (variant)
8.10438

Malwarebytes
v2014.09.19.07

Reason Heuristics
Adware.Yontoo.ClearThink.X
14.9.19.19

VIPRE Antivirus
Yontoo
33232

File size:
41.2 KB (42,224 bytes)

Product version:
0.0.0.0

Original file name:
ClearThinkBrowserFilter.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\clearthink\bin\clearthinkbrowserfilter.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2014 9:00:00 PM

Valid to:
8/5/2015 8:59:59 PM

Subject:
CN=ClearThink, O=ClearThink, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1200063ED04B1DA36F7FE204B3DD8617

File PE Metadata
Compilation timestamp:
9/18/2014 6:56:41 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:FpvvxbCXFl1jIW4600m8NLFPSDVYN/xNYD:FtxuXPyWfDPSDI/rE

Entry address:
0xA036

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
32.5 KB (33,280 bytes)

Remove ClearThinkBrowserFilter.exe - Powered by Reason Core Security