laflurlabho.dll

Laflurla

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module laflurlabho.dll by Laflurla has been detected as adware by 34 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Laflurla’. Additionally, the file is typically installed by a number of programs including Laflurla by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Laflurla  (signed and verified)

Product:
Laflurla

Version:
1.0.0.3

MD5:
4593f6ea01f57de729144c7be8e4d9ab

SHA-1:
4ef0de93d73cdd184fd449737e731831506dedbe

SHA-256:
5a8d8b6da99d4b37211f37faf95cd678f239271a0734b318627f7b40955455be

Scanner detections:
34 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/20/2024 3:24:01 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.BHO.Agent.4
869

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.172.150

avast!
Win32:BrowseFox-AX [PUP]
2014.9-140918

AVG
BrowseFox.F
2015.0.3347

Baidu Antivirus
Adware.Win32.Agent
4.0.3.14918

Bitdefender
Gen:Variant.Adware.BHO.Agent.4
1.0.20.1305

Comodo Security
Application.Win32.Altbrowse.AK
19531

Dr.Web
Trojan.BPlug.28
9.0.1.0261

Emsisoft Anti-Malware
Gen:Variant.Adware.BHO.Agent
8.14.09.18.03

ESET NOD32
Win32/BrowseFox (variant)
8.10426

Fortinet FortiGate
Adware/Agent
9/18/2014

F-Prot
W32/BadBHO.AW.gen
v6.4.7.1.166

F-Secure
Gen:Variant.Adware.BHO.Agent.4
11.2014-18-09_5

G Data
Gen:Variant.Adware.BHO.Agent
14.9.24

herdProtect (fuzzy)
2014.11.25.3

IKARUS anti.virus
not-a-virus:AdWare.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.183.13393

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3232

Malwarebytes
PUP.Optional.Laflurla.A
v2014.09.18.03

McAfee
Artemis!5203B29EAD37
5600.7003

MicroWorld eScan
Gen:Variant.Adware.BHO.Agent.4
15.0.0.783

NANO AntiVirus
Riskware.Win32.Agent.cuenda
0.28.2.61942

nProtect
Trojan-Clicker/W32.Agent.249632.C
14.09.16.01

Panda Antivirus
Trj/CI.A
14.09.18.03

Qihoo 360 Security
Malware.Radar03.Gen
1.0.0.1015

Quick Heal
AdWare.Agent.r5 (Not a Virus)
9.14.12.00

Reason Heuristics
Adware.Yontoo.BHO.L
14.9.18.15

Sophos
Generic PUA EO
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
10352

Trend Micro House Call
TROJ_GEN.F47V0423
7.2.261

Vba32 AntiVirus
AdWare.Agent
3.12.26.0

VIPRE Antivirus
Yontoo
33170

Zillya! Antivirus
Adware.Agent.Win32.9009
2.0.0.1798

File size:
243.8 KB (249,632 bytes)

Product version:
1.0.0.3

Copyright:
(c) Laflurla. All rights reserved.

Original file name:
LaflurlaIEClient.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\laflurla\laflurlabho.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/3/2014 5:00:00 PM

Valid to:
2/4/2015 4:59:59 PM

Subject:
CN=Laflurla, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Laflurla, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0541E25DBE69A2BC84C39AB35093A301

File PE Metadata
Compilation timestamp:
7/5/2014 11:19:54 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:67w3txaAf0ZP0Thn+BClmD5pdM21m+2IIaI48nckpIe:67w6ZQd+n2JIIPc4Ie

Entry address:
0x12844

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 20, 2D, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 04, 68, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 7C, A1, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3660

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
Laflurla

CLSID:
{b4a89cd3-c5f5-49c4-abcf-5f26d636476f}


The file laflurlabho.dll has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Laflurla  by Yontoo Technology, Inc.
The software injects advertisements in the user's web browser. "You are seeing Laflurla ads because you installed Laflurla on your computer. In order to keep Laflurla free, it is supported by advertisements on the websites on which it functions.
www.laflurla.com/review#ata
88% remove it
 
Powered by Should I Remove It?

Remove laflurlabho.dll - Powered by Reason Core Security