jqvqaafc8rbzex.x64.dll

The module jqvqaafc8rbzex.x64.dll has been detected as a potentially unwanted program by 25 anti-malware scanners. Additionally, the file is typically installed by a number of programs including DiscountLocator by InstalleRex-WebPick and ApptoU by InstalleRex-WebPick , both potentially unwanted software.
MD5:
388feac0c3abaf35d451edd34e89b2d4

SHA-1:
564e5f05143e29e5de4f202dd9c6f36b05b3bcb3

SHA-256:
80df3798ceffbe51714b7c4ff96ea22847e9c1f1d4f278ec56396635cde59acd

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 4:31:22 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Generic.1013617
684

Agnitum Outpost
PUA.MultiPlug
7.1.1

Avira AntiVirus
ADWARE/Adware.Gen
7.11.219.10

avast!
Win64:PUP-gen [PUP]
2014.9-150323

AVG
Generic6
2016.0.3162

Baidu Antivirus
Adware.Win32.MultiPlug
4.0.3.15323

Bitdefender
Application.Generic.1013617
1.0.20.410

Comodo Security
ApplicUnwnt
21494

ESET NOD32
Win64/Adware.MultiPlug (variant)
8.10910

Fortinet FortiGate
Adware/MultiPlug
3/23/2015

F-Secure
Application.Generic.1013617
11.2015-23-03_2

G Data
Application.Generic.1013617
15.3.25

K7 AntiVirus
Adware
13.202.15339

Kaspersky
not-a-virus:AdWare.Win64.MultiPlug
14.0.0.2304

Malwarebytes
PUP.Optional.Multiplug
v2015.03.23.04

McAfee
RDN/Generic PUP.x!cqv
5600.6818

Microsoft Security Essentials
BrowserModifier:Win32/CouponRuc
1.1.11400.0

MicroWorld eScan
Application.Generic.1013617
16.0.0.246

NANO AntiVirus
Riskware.Win64.MultiPlug.dlmbha
0.30.8.659

Reason Heuristics
Threat.Win.Reputation.IMP
14.12.21.10

Trend Micro House Call
TROJ_FRS.PMA000AB15
7.2.82

Trend Micro
TROJ_FRS.PMA000AB15
10.465.23

Vba32 AntiVirus
AdWare.Win64.MultiPlug
3.12.26.3

VIPRE Antivirus
Win64.Adware.MultiPlug
38652

Zillya! Antivirus
Adware.MultiPlug.Win64.259
2.0.0.2110

File size:
639 KB (654,336 bytes)

Copyright:
Copyright (C) 2014

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Common path:
C:\Program Files\buynsave\jqvqaafc8rbzex.x64.dll

Registration
CLSID:
{1f0f203d-3549-4f6c-aad2-93b0bca37402}

ProgID:
BuyNsave.9

COM registered:
Yes

File PE Metadata
Compilation timestamp:
11/10/2014 3:12:03 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:jWBFcPZSTIfS891Hd0TkbJGRYq4Ie37JzDaqFjSaRHDTXCbt8UzU5rpB9UC8gSKM:jWB8ECtJGeXIezVSCxp3U4xsX

Entry address:
0x55E48

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, F7, 5D, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, 03, 00, 00, 00, CC, CC, CC, 48, 8B, C4, 48, 89, 58, 20, 4C, 89, 40, 18, 89, 50, 10, 48, 89, 48, 08, 56, 57, 41, 56, 48, 83, EC, 50, 49, 8B, F0, 8B, DA, 4C, 8B, F1, BA, 01, 00, 00, 00, 89, 50, B8, 85, DB, 75, 0F, 39, 1D, 9C, 57, 04, 00, 75, 07, 33, C0, E9, D2, 00, 00, 00, 8D, 43, FF...
 
[+]

Code size:
393 KB (402,432 bytes)

The file jqvqaafc8rbzex.x64.dll has been discovered within the following programs.

ApptoU  by InstalleRex-WebPick
AppToU is an adware program that will display extra advertisements when users are using search engines such as Bing and Google. In Chrome, it installs itself as an extension and in Internet Explorer it runs as a process as well as a Browser Helper Object.
83% remove it
DiscountLocator  by InstalleRex-WebPick
DiscountLocator is an adware program that will display extra advertisements when users are using search engines such as Bing and Google. In Chrome, it installs itself as an extension and in Internet Explorer it runs as a process as well as a Browser Helper Object.
79% remove it
 
Powered by Should I Remove It?

Remove jqvqaafc8rbzex.x64.dll - Powered by Reason Core Security