phpnukeeng.dll

PHPNuke Toolbar

Montera Technologeis LTD

This is part of the Montera web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The module phpnukeeng.dll by Montera Technologeis has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
PHPNuke.org  (signed by Montera Technologeis LTD)

Product:
PHPNuke Toolbar

Version:
1.8.13.0

MD5:
eb9c7a9ddd86a52d7ed83319693a87ae

SHA-1:
94049d147e8a884cced2ccf4405deb8c1b514105

SHA-256:
74aebeafbfe051b93b21a90dccb927b48be29dda9c9120ac1453f1d2d69984e6

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 11:31:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera.Montera.Toolbar (M)
16.2.5.10

File size:
591.9 KB (606,104 bytes)

Product version:
1.8.13.0

Copyright:
(c) PHPNuke.org All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\phpnuke\phpnuke\1.8.12.1\phpnukeeng.dll

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/27/2012 7:00:00 PM

Valid to:
5/28/2013 6:59:59 PM

Subject:
CN=Montera Technologeis LTD, O=Montera Technologeis LTD, STREET="18, Amammi st", L=Even Yehuda, S=Hasharon, PostalCode=40500, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
361B49E5431DD304CA32589D28E4DD3C

File PE Metadata
Compilation timestamp:
2/7/2013 7:52:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:dYuYQNGQdWRXZU9beGcZpaZJkpupwnwu6U5bi4rX8i4Rb9gjoSfHUeGpvLwe4l4N:dY1Q+pLcmt8i4RmdPupvLvRJz

Entry address:
0x478E5

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 78, 9C, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, E8, B2, 58, 00, 00, FF, 75, 10, 83, C0, 20, 50, FF, 75, 0C, FF, 75, 08, E8, E4, 9C, 00, 00, 83, C4, 10, 5D, C3, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 0C, FF, 75, 08, E8, CD, FF, FF, FF, 83, C4, 0C, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, 83, 65, FC, 00, 56, 8B, 75, 08, 85, F6, 75, 16, E8, 7B, 3B, 00, 00, 6A, 16, 5E, 89, 30, E8, 1F, 3B, 00, 00, 8B, C6...
 
[+]

Entropy:
6.4136

Code size:
391.5 KB (400,896 bytes)

Remove phpnukeeng.dll - Powered by Reason Core Security