gatesnapper.dll

gate snapper

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module gatesnapper.dll by gate snapper has been detected as adware by 5 anti-malware scanners. This file is typically installed with the program gate snapper by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. The file has been seen being downloaded from install-cdn.gatesnapper.com.
Publisher:
gate snapper  (signed and verified)

Product:
gate snapper

Version:
1.0.0.7

MD5:
484a451e7305f57c8a5cef85ffd97af8

SHA-1:
0bb7f333891ba3a128e902c442b2219b0985065a

SHA-256:
5eeb312b4a69610d469a754860eaf09648ac0a7aab4ac2866b78b1460ce31b6d

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
5/5/2024 8:36:13 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.206.52

AVG
Generic
2016.0.3213

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15131

Malwarebytes
PUP.Optional.GateSnapper.A
v2015.01.31.08

Reason Heuristics
Threat.Win.Reputation.IMP
15.1.31.8

File size:
262.7 KB (269,048 bytes)

Product version:
1.0.0.7

Copyright:
(c) gate snapper. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\k9zl6y6a\gatesnapper.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/19/2014 4:00:00 PM

Valid to:
11/20/2015 3:59:59 PM

Subject:
CN=gate snapper, O=gate snapper, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
133A7A0373BA5F8F11B450D044B92146

File PE Metadata
Compilation timestamp:
1/30/2015 2:31:42 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:imiYckxqEbUViVqUsVNXBB+/nFK3wY+lx9ZKTLhKjycEZ:imiYckziiVMrXFdI9Z4YBq

Entry address:
0xF515

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, EA, 7E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, D8, 21, 03, 10, E8, 4C, 02, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 4C, 77, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, C4, 93, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.0736

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file gatesnapper.dll has been discovered within the following programs.

gate snapper  by Yontoo Technology, Inc.
This is browser adware. It installs in the user's web browser and while running will display unwanted ads from malicious software and other adware. It is bundled through download managers.
gatesnapper.com/support
87% remove it
 
Powered by Should I Remove It?

The file gatesnapper.dll has been seen being distributed by the following URL.

Remove gatesnapper.dll - Powered by Reason Core Security