jbqjsrigah.dll

Acute Angle Solutions Ltd.

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The module jbqjsrigah.dll by Acute Angle Solutions has been detected as adware by 16 anti-malware scanners.
Publisher:
Acute Angle Solutions Ltd.  (signed and verified)

MD5:
eb93886f5f7857d80d5161e42317faf9

SHA-1:
a756566923a096883219c7d5b857d1402bf02334

SHA-256:
618299385cc7a4bb417e0ac11244bb6d621e4975114c1a25fde162f6ebd2f110

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/16/2024 9:07:03 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.PullUpdate.B
865

Avira AntiVirus
ADWARE/Adware.Gen
7.11.173.208

AVG
Acute
2015.0.3343

Baidu Antivirus
Adware.MSIL.PullUpdate
4.0.3.14922

Bitdefender
Adware.PullUpdate.B
1.0.20.1325

Emsisoft Anti-Malware
Adware.PullUpdate
8.14.09.22.02

ESET NOD32
MSIL/Adware.PullUpdate.C application
8.7.0.302.0

F-Secure
Adware.PullUpdate.B
11.2014-22-09_2

G Data
Adware.PullUpdate
14.9.24

herdProtect (fuzzy)
2014.12.4.17

K7 AntiVirus
Adware
13.183.13451

MicroWorld eScan
Adware.PullUpdate.B
15.0.0.795

nProtect
Adware.PullUpdate.B
14.09.22.01

Reason Heuristics
PUP.AcuteAngleSolutions.K
14.9.22.12

Sophos
Pull Update
4.98

VIPRE Antivirus
Threat.4784449
33120

File size:
1.1 MB (1,186,176 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\ProgramData\ebsrpako\dat\jbqjsrigah.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/30/2014 6:00:00 PM

Valid to:
1/31/2015 5:59:59 PM

Subject:
CN=Acute Angle Solutions Ltd., OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Acute Angle Solutions Ltd., L=St. James, S=St. James, C=BB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0A7A77148C6F7A33F9174DA187F6FEF0

File PE Metadata
Compilation timestamp:
9/11/2014 7:29:14 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:PG1H5zeCK19B2G8i5UvGuoe5vLBpWMD6xZjzMHop/xU3Tv:+5W1CniOvEMD6xN9/CT

Entry address:
0xB0C74

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 42, C1, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 80, 00, 00, 00, 72, 0E, 83, 3D, 34, 91, 11, 45, 00, 74, 05, E9, 95, C1, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03...
 
[+]

Entropy:
6.2698

Code size:
820.5 KB (840,192 bytes)

Remove jbqjsrigah.dll - Powered by Reason Core Security