plugin.exe

Crazy Score

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application plugin.exe by Crazy Score has been detected as adware by 25 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Crazy Score  (signed and verified)

Version:
1.0.5625.12074

MD5:
1fff79cf4c0afc37e8fcff0fc8efdb38

SHA-1:
6e219b3803a0602746ee16e3b13f18ee6267d0bf

SHA-256:
1986c0aa98e957805438f8ac7c949bc5c31d9ff77533058e564ab973ceb0198c

Scanner detections:
25 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 9:03:55 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.CW
5566587

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.05.28

Avira AntiVirus
ADWARE/BrowseFox.Gen
8.3.1.6

AVG
Adware AdPlugin.DNV
2014.0.4311

Bitdefender
Adware.BrowseFox.CW
1.0.20.740

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Browsefox-913
0.98/20509

Comodo Security
Application.Win32.BrowseFox.AKF
22250

Dr.Web
Trojan.Yontoo.1837
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.CW
10.0.0.5366

ESET NOD32
Win32/BrowseFox.AF potentially unwanted application
7.0.302.0

F-Prot
W32/S-b638c0c1
v6.4.7.1.166

F-Secure
Adware.BrowseFox.CW
5.14.151

G Data
Adware.BrowseFox.CW
15.5.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.9.2.0

K7 AntiVirus
Unwanted-Program
13.204.16051

McAfee
Program.BrowseFox-FYS
18.0.204.0

MicroWorld eScan
Adware.BrowseFox.CW
16.0.0.444

NANO AntiVirus
Riskware.Win32.Agent.drgxoz
0.30.24.1636

nProtect
Adware.BrowseFox.CW
15.05.27.01

Reason Heuristics
PUP.Yontoo.CrazyScore
15.5.27.23

Vba32 AntiVirus
AdWare.Agent
3.12.26.4

VIPRE Antivirus
Threat.5061968
40552

Zillya! Antivirus
Backdoor.PePatch.Win32.71460
2.0.0.2192

File size:
469.3 KB (480,520 bytes)

Product version:
1.0.5625.12074

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3bak\plugin.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/6/2015 4:00:00 AM

Valid to:
3/6/2016 3:59:59 AM

Subject:
CN=Crazy Score, O=Crazy Score, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
787CCA0851A6106E9FCB411D35B4D2A0

File PE Metadata
Compilation timestamp:
5/27/2015 5:42:43 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:qpCAxYpRfmxPqmL4s1WvPQiIJ34dAOIf3E1u2fl:bVpRfmxPZLTWXnGuIfyuU

Entry address:
0x28148

Entry point:
E8, 6C, F8, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 8A, F9, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 74, F9, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, 80, E2, 46, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D, 8B, 4F, 04, 03, CE, 33, 0C, 30, E8, B0, D0, FF, FF, 8B...
 
[+]

Code size:
356.5 KB (365,056 bytes)

Remove plugin.exe - Powered by Reason Core Security