plugin.exe

Strong Signal

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application plugin.exe by Strong Signal has been detected as adware by 26 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Strong Signal  (signed and verified)

Version:
1.0.5624.39046

MD5:
2e5acf16d9a7fdb3b0c778ab0ee471f8

SHA-1:
3a8707c1ce5063d4638e4585c44c2ac3d3cc7097

SHA-256:
a203934e7badb2f5383f23307ec1ca92f66ece73f17017b8b6ef29e66a29912d

Scanner detections:
26 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 3:09:40 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.CW
5566587

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.05.28

Avira AntiVirus
ADWARE/BrowseFox.Gen
8.3.1.6

AVG
Adware AdPlugin.DNV
2014.0.4311

Bitdefender
Adware.BrowseFox.CW
1.0.20.735

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Browsefox-913
0.98/21511

Comodo Security
Application.Win32.BrowseFox.AKF
22250

Dr.Web
Trojan.Yontoo.1735
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.CW
10.0.0.5366

ESET NOD32
Win32/BrowseFox.AF potentially unwanted application
7.0.302.0

F-Prot
W32/S-b638c0c1
v6.4.7.1.166

F-Secure
Adware.BrowseFox.CW
5.14.151

G Data
Adware.BrowseFox.CW
15.5.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.9.2.0

K7 AntiVirus
Unwanted-Program
13.204.16051

Malwarebytes
PUP.Optional.StrongSignal.SID.A
v2015.05.27.11

McAfee
BrowseFox-FYS
5600.6752

MicroWorld eScan
Adware.BrowseFox.CW
16.0.0.441

NANO AntiVirus
Riskware.Win32.Agent.drgxoz
0.30.24.1636

nProtect
Adware.BrowseFox.CW
15.05.27.01

Reason Heuristics
PUP.Yontoo.StrongSignal
15.5.27.23

Sophos
PUA 'Browse Fox'
5.14

Vba32 AntiVirus
AdWare.Agent
3.12.26.4

VIPRE Antivirus
Threat.4741131
40552

Zillya! Antivirus
Backdoor.PePatch.Win32.71460
2.0.0.2192

File size:
469.3 KB (480,528 bytes)

Product version:
1.0.5624.39046

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\0780f478-67ce-4ec3-98db-39a65f4618ce\plugins\3bak\plugin.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
12/11/2014 5:00:00 PM

Valid to:
12/12/2015 4:59:59 PM

Subject:
CN=Strong Signal, O=Strong Signal, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5047EE0477D4F273DFC93DB8A749B9E0

File PE Metadata
Compilation timestamp:
5/26/2015 9:41:45 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:lpCAxYpRfmxPqmL4s1WvPQiIJ34dA/ri3E1uFfA:CVpRfmxPZLTWXnGfriyui

Entry address:
0x28148

Entry point:
E8, 6C, F8, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 8A, F9, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 74, F9, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, 80, E2, 46, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D, 8B, 4F, 04, 03, CE, 33, 0C, 30, E8, B0, D0, FF, FF, 8B...
 
[+]

Entropy:
6.5507

Code size:
356.5 KB (365,056 bytes)

Remove plugin.exe - Powered by Reason Core Security