plugin.exe

Crazy Score

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application plugin.exe by Crazy Score has been detected as adware by 24 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Crazy Score  (signed and verified)

Version:
1.0.5617.17433

MD5:
639d118cdd8ec6de5b03fbe84ec2f70f

SHA-1:
6e33d77d8294ad6b83ee641f785920430c8c2cd5

SHA-256:
5ffd887c5be26ec2cf987e257a011b123fad9b6de6a9dd5203094dea05b3edda

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 5:04:16 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.CW
5547725

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.05.23

Avira AntiVirus
ADWARE/BrowseFox.Gen
8.3.1.6

AVG
Adware AdPlugin.DNV
2014.0.4311

Bitdefender
Adware.BrowseFox.CW
1.0.20.715

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Browsefox-913
0.98/20500

Dr.Web
Trojan.Yontoo.1837
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.CW
10.0.0.5366

ESET NOD32
Win32/BrowseFox.AF potentially unwanted application
7.0.302.0

F-Prot
W32/S-b638c0c1
v6.4.7.1.166

F-Secure
Adware.BrowseFox.CW
5.14.151

G Data
Adware.BrowseFox.CW
15.5.25

K7 AntiVirus
Unwanted-Program
13.204.16007

McAfee
Trojan.Artemis!639D118CDD8E
18.0.204.0

MicroWorld eScan
Adware.BrowseFox.CW
16.0.0.429

NANO AntiVirus
Riskware.Win32.Agent.drgxoz
0.30.24.1636

nProtect
Adware.BrowseFox.CW
15.05.22.01

Reason Heuristics
PUP.Yontoo.CrazyScore
15.5.23.6

Sophos
Generic PUA GO
4.98

Vba32 AntiVirus
AdWare.Agent
3.12.26.4

VIPRE Antivirus
Threat.4150696
40432

Zillya! Antivirus
Backdoor.PePatch.Win32.71460
2.0.0.2187

File size:
469.3 KB (480,520 bytes)

Product version:
1.0.5617.17433

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3bak\plugin.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/6/2015 1:00:00 AM

Valid to:
3/6/2016 12:59:59 AM

Subject:
CN=Crazy Score, O=Crazy Score, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
787CCA0851A6106E9FCB411D35B4D2A0

File PE Metadata
Compilation timestamp:
5/19/2015 6:41:21 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:ypCAxYpRfmxPqmL4s1WvPQiIJ34dAOYZ3E1uDfJ:jVpRfmxPZLTWXnGuYZyuF

Entry address:
0x28148

Entry point:
E8, 6C, F8, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 8A, F9, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 74, F9, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, 80, E2, 46, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D, 8B, 4F, 04, 03, CE, 33, 0C, 30, E8, B0, D0, FF, FF, 8B...
 
[+]

Code size:
356.5 KB (365,056 bytes)

Remove plugin.exe - Powered by Reason Core Security