{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}gw64.sys

SmarterPower

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}gw64.sys by SmarterPower has been detected as adware by 19 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}Gw64”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
StdLib  (signed by SmarterPower)

Product:
StdLib

Version:
1.4.4.6 built by: WinDDK

MD5:
91c97b98162d8df58d4c7aa071297402

SHA-1:
edd69fcd901515349553401ebcefa1fe14723992

SHA-256:
0fb28b0bcb8719920102a9389936c8b0e605177641cf4a2740483ddb1f0832d8

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 3:54:35 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.CH
826

Agnitum Outpost
Riskware.Agent
7.1.1

AVG
Generic
2015.0.3304

Baidu Antivirus
Adware.Win64.BrowseFox
4.0.3.14111

Bitdefender
Adware.SwiftBrowse.CH
1.0.20.1525

Clam AntiVirus
Win.Adware.Swiftbrowse-497
0.98/21411

Dr.Web
Tool.NetFilter.313
9.0.1.0305

Emsisoft Anti-Malware
Adware.SwiftBrowse.CH
8.14.11.01.07

ESET NOD32
Win64/BrowseFox (variant)
8.10583

Fortinet FortiGate
Adware/BrowseFox
11/1/2014

F-Secure
Adware.SwiftBrowse.CH
11.2014-01-11_7

G Data
Adware.SwiftBrowse.CH
14.11.24

K7 AntiVirus
Trojan
13.184.13727

McAfee
Artemis!91C97B98162D
5600.6960

MicroWorld eScan
Adware.SwiftBrowse.CH
15.0.0.915

nProtect
Adware.SwiftBrowse.CH
14.10.17.01

Reason Heuristics
PUP.SmarterPower.n
14.11.1.7

Sophos
Browse Fox
4.98

VIPRE Antivirus
Trojan.Win32.Generic
34036

File size:
47.6 KB (48,792 bytes)

Product version:
1.4.4.6

Copyright:
Copyright © 2013 StdLib

Original file name:
StdLib.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}gw64.sys

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2014 8:00:00 PM

Valid to:
8/5/2015 7:59:59 PM

Subject:
CN=SmarterPower, O=SmarterPower, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38D7C83A73CB4E3AC85648608E3170D8

File PE Metadata
Compilation timestamp:
9/22/2014 3:01:54 PM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:lC7G2EjsnyXeOUEGG0LA8tWFZuL470h6aqxcCT2kvsVRwlZD3IUznf:gFID6EGnLA8AFJTNEVmDI

Entry address:
0xC064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, E2, 50, FF, FF, CC, CC, 78, C2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 54, C6, 00, 00, A0, 91, 00, 00, 28, C1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DA, CA, 00, 00, 50, 90, 00, 00, D8, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D2, CB, 00, 00, 00, 90, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, CB, 00, 00, 00, 00, 00, 00, A2, CB, 00, 00...
 
[+]

Entropy:
6.3915

Code size:
34.5 KB (35,328 bytes)

Driver
Display name:
{fa50efa5-2c2a-4d8c-b58d-b9548ceccd2b}Gw64

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI