glindorusBrowserFilter.exe

glindorus

Installed as part of the Yontoo glindorus branded web browser extension, the BrowserFilter component is responsible for injecting advertising in the browser based on the context of the HTML being rendered. Ads are injected in the browser in the form of inline text, coupons, multi-site searching and additional offers. The application glindorusBrowserFilter.exe by glindorus has been detected as adware by 5 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
glindorus  (signed and verified)

Version:
0.0.0.0

MD5:
1ed8ebe5ebeda18467618353127998a4

SHA-1:
90c86b338d9e81b2fa4bbf8d7673934173119d4f

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/24/2024 1:02:37 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
MalSign.Skodna.glindorus
2015.0.3496

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14423

ESET NOD32
MSIL/BrowseFox (variant)
8.9711

Malwarebytes
v2014.04.23.09

Reason Heuristics
Adware.Yontoo.glindorus.W
14.8.7.21

File size:
41.3 KB (42,272 bytes)

Product version:
0.0.0.0

Original file name:
glindorusBrowserFilter.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\glindorus\bin\glindorusbrowserfilter.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/19/2013 2:00:00 AM

Valid to:
9/20/2015 1:59:59 AM

Subject:
CN=glindorus, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=glindorus, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38CA8426D3AC22743D3790B6CAB486B4

File PE Metadata
Compilation timestamp:
3/5/2014 3:34:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:wxVnms7uAfO3oN6axbC3HMci8UAfXTaR3gxyk6y8CaSFQWB5mIfRcZ7f5VqL/myY:qzLTxbCXFl1jIW580QWBBIT5VYN/HsW

Entry address:
0xA036

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
32.5 KB (33,280 bytes)

Remove glindorusBrowserFilter.exe - Powered by Reason Core Security