fasterlightun.exe

Follow Rules

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application fasterlightun.exe by Follow Rules has been detected as adware by 20 anti-malware scanners. This file is typically installed with the program Faster Light by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Follow Rules  (signed and verified)

Version:
1.0.0.0

MD5:
437d20b33501fdce6a0fb8d5ad4df910

SHA-1:
a8b468effc32cca9bb900f24308b1d7ba7277224

SHA-256:
8d1200f6d23beb1f2c56b553b06cffc6c297ae5071e3dffedc660f0464376e3f

Scanner detections:
20 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/18/2024 2:00:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.CD
680

Agnitum Outpost
Riskware.Agent
7.1.1

Avira AntiVirus
ADWARE/BrowseFox.Gen4
7.11.218.230

avast!
MSIL:BrowseFox-S [PUP]
2014.9-150327

AVG
Generic
2016.0.3158

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.15327

Bitdefender
Adware.BrowseFox.CD
1.0.20.430

Dr.Web
Trojan.Yontoo.1734
9.0.1.086

Emsisoft Anti-Malware
Adware.BrowseFox.CD
8.15.03.27.06

ESET NOD32
MSIL/BrowseFox.G potentially unwanted (variant)
9.11354

F-Secure
Adware.BrowseFox.CD
11.2015-27-03_6

G Data
Adware.BrowseFox.CD
15.3.25

K7 AntiVirus
Trojan
13.202.15333

Malwarebytes
PUP.Optional.FasterLight.A
v2015.03.27.06

nProtect
Adware.BrowseFox.CD
15.03.20.01

Qihoo 360 Security
Win32/Virus.Adware.650
1.0.0.1015

Reason Heuristics
PUP.Yontoo
15.3.27.6

Sophos
Generic PUA KI
4.98

Trend Micro House Call
Suspicious_GEN.F47V0316
7.2.86

VIPRE Antivirus
Yontoo
38614

File size:
546.7 KB (559,856 bytes)

Product version:
1.0.0.0

Original file name:
Faster Light Uninstaller.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\faster light\fasterlightun.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/11/2015 1:00:00 AM

Valid to:
1/12/2016 12:59:59 AM

Subject:
CN=Follow Rules, O=Follow Rules, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
360C16AC576B09F5DFA927EA0089856F

File PE Metadata
Compilation timestamp:
3/11/2015 5:22:42 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:6PzDmjmvmq/l2WrZ2Al3O8VRHSIKBLJEd/vjSmIi1KMXlhp4dZLH9uU9aCSoNNzi:6PzDmjmvmq/lHQc3TVN/V9JSpNhhvnWX

Entry address:
0x86A53

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
531 KB (543,744 bytes)

The file fasterlightun.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Faster Light  by Yontoo Technology, Inc.
Faster Light is an ad-supported browser extension that may deliver advertisements in the form of coupons, affiliate links, price-comparisons, display media and other links through a number of functions including those based on the the content of any web page the user is visiting, plug-ins, add-ons, or the web browser itself.
fasterlight.info/support
86% remove it
 
Powered by Should I Remove It?

Remove fasterlightun.exe - Powered by Reason Core Security