plugin.exe

Assist Point

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application plugin.exe by Assist Point has been detected as adware by 23 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Assist Point  (signed and verified)

Version:
1.0.5620.1258

MD5:
5425f054e505c4bc4ca3e8aaebdff190

SHA-1:
d455705b6699b44a10ec0a780b7ebc3815d5bbc5

SHA-256:
3ef4aff796c369c3f252fcb01fb8ff3492b7dd7f3621323e824a1b113634da16

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 7:49:14 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.CW
5549295

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.05.23

Avira AntiVirus
ADWARE/BrowseFox.Gen
8.3.1.6

AVG
Adware AdPlugin.DNV
2014.0.4311

Bitdefender
Adware.BrowseFox.CW
1.0.20.710

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Browsefox-913
0.98/20498

Dr.Web
Trojan.Yontoo.1781
9.0.1.05190

Emsisoft Anti-Malware
Adware.BrowseFox.CW
10.0.0.5366

ESET NOD32
Win32/BrowseFox.AF potentially unwanted application
7.0.302.0

F-Prot
W32/S-cfd541ab
v6.4.7.1.166

F-Secure
Adware.BrowseFox.CW
5.14.151

G Data
Adware.BrowseFox.CW
15.5.25

K7 AntiVirus
Unwanted-Program
13.204.16000

Malwarebytes
PUP.Optional.AssistPoint.A
v2015.05.22.03

MicroWorld eScan
Adware.BrowseFox.CW
16.0.0.426

NANO AntiVirus
Riskware.Win32.Agent.drgxoz
0.30.24.1636

nProtect
Adware.BrowseFox.CW
15.05.22.01

Reason Heuristics
PUP.Yontoo.AssistPoint
15.5.22.10

Sophos
PUA 'Browse Fox'
5.14

VIPRE Antivirus
Threat.4150696
40432

Zillya! Antivirus
Backdoor.PePatch.Win32.71460
2.0.0.2187

File size:
469.3 KB (480,528 bytes)

Product version:
1.0.5620.1258

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\c716fd70-872c-4aaa-a07f-e248365d7f56\plugins\3\plugin.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/6/2015 1:00:00 AM

Valid to:
3/6/2016 12:59:59 AM

Subject:
CN=Assist Point, O=Assist Point, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
58FC58A52C291B337067DC6AA50B8FB3

File PE Metadata
Compilation timestamp:
5/22/2015 9:42:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
12288:WpCAxYpRfmxPqmL4s1WvPQiIJ34dAN6x3E1uTf:fVpRfmxPZLTWXnGt6xyu

Entry address:
0x28148

Entry point:
E8, 6C, F8, 00, 00, E9, 7F, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 8A, F9, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 74, F9, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, 80, E2, 46, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8, FE, 74, 0D, 8B, 4F, 04, 03, CE, 33, 0C, 30, E8, B0, D0, FF, FF, 8B...
 
[+]

Code size:
356.5 KB (365,056 bytes)

Remove plugin.exe - Powered by Reason Core Security