plsapplsp64.exe

plsappLSP64.exe

Sendori, LLC

This is part of the Sendori web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application plsapplsp64.exe by Sendori has been detected as adware by 11 anti-malware scanners. This file is typically installed with the program PureLeads by Sendori, LLC which is a potentially unwanted software program.
Publisher:
Sendori  (signed by Sendori, LLC)

Product:
plsappLSP64.exe

Description:
RegisterLSP

Version:
2.2.9.1

MD5:
70cc13e1b471e0aeddf45374e69375a6

SHA-1:
27a5d67631f7d2244cce21d60bcaa6d9f0dc5246

SHA-256:
ba6c59544936ad3c0f65b76952363bbc4668536774e56fdf220fb8f453fee915

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
4/26/2024 6:30:43 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Sendori.E
939

Bitdefender
Adware.Sendori.E
1.0.20.960

Emsisoft Anti-Malware
Adware.Sendori
8.14.07.11.06

ESET NOD32
Win32/AdWare.Sendori (variant)
8.10023

F-Secure
Adware.Sendori.E
11.2014-11-07_6

G Data
Adware.Sendori
14.7.24

MicroWorld eScan
Adware.Sendori.E
15.0.0.576

Norman
Sendori.CERT
11.20140711

nProtect
Adware.Sendori.E
14.06.30.01

Reason Heuristics
PUP.Sendori.L
14.8.7.19

VIPRE Antivirus
Sendori
30820

File size:
400.8 KB (410,400 bytes)

Product version:
2.2.9.1

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\pureleads\plsapplsp64.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/9/2013 7:00:00 PM

Valid to:
12/10/2014 6:59:59 PM

Subject:
CN="Sendori, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Sendori, LLC", L=Oakland, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
310642A25A6D9FB4A7E88E32D87A345F

File PE Metadata
Compilation timestamp:
6/3/2014 12:13:12 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
9.0

CTPH (ssdeep):
6144:OHDSRe/u1YBmfUqaNRKJDWCW1k3NZBJM08kjMLXFY0GtwLhlpH4:OjSe9tqAn1XLXFYZ

Entry address:
0x31610

Entry point:
48, 83, EC, 28, E8, 97, 9C, 00, 00, 48, 83, C4, 28, E9, 56, FE, FF, FF, CC, CC, 48, 89, 54, 24, 10, 4C, 89, 44, 24, 18, 4C, 89, 4C, 24, 20, 53, 48, 83, EC, 60, 48, 85, D2, 75, 25, E8, 82, 05, 00, 00, 48, 83, 64, 24, 20, 00, 45, 33, C9, 45, 33, C0, 33, D2, 33, C9, C7, 00, 16, 00, 00, 00, E8, BB, DA, FF, FF, 83, C8, FF, EB, 55, 48, 85, C9, 74, D6, 48, 89, 4C, 24, 40, 48, 89, 4C, 24, 30, 4C, 8D, 8C, 24, 80, 00, 00, 00, 48, 8D, 4C, 24, 30, 45, 33, C0, C7, 44, 24, 38, FF, FF, FF, 7F, C7, 44, 24, 48, 42, 00, 00...
 
[+]

Entropy:
6.1158

Code size:
283 KB (289,792 bytes)

The file plsapplsp64.exe has been discovered within the following program.

PureLeads  by Sendori, LLC
This adware program injects advertisements with its affiliate ad providers in order to serve a number of ad types including banner, inline text links and popups.
pureleads.com
72% remove it
 
Powered by Should I Remove It?

Remove plsapplsp64.exe - Powered by Reason Core Security