roundworld.dll

Round World

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module roundworld.dll by Round World has been detected as adware by 24 anti-malware scanners. This file is typically installed with the program Round World by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. The file has been seen being downloaded from install-cdn.myroundworld.com and multiple other hosts.
Publisher:
Round World  (signed and verified)

Product:
Round World

Version:
1.0.0.7

MD5:
2b6e11bb341d856690f5fa8ad8900bbc

SHA-1:
7c11425d259bd65264ce000d36318c8067737b91

SHA-256:
24f1af11d6eaffeb20f850bb65ced663faf27e9c27e60256a476ce0fcc0a2e9d

Scanner detections:
24 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/28/2024 9:35:58 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BJ
600

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.212.102

avast!
Win32:BrowseFox-DZ [PUP]
2014.9-150614

AVG
Generic
2016.0.3177

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1538

Bitdefender
Adware.BrowseFox.BJ
1.0.20.825

Bkav FE
W32.HfsAdware
1.3.0.6379

Dr.Web
Trojan.Yontoo.1016
9.0.1.05190

ESET NOD32
Win32/BrowseFox.AE potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/BrowseFox
3/8/2015

F-Prot
W32/S-f64f6ec1
v6.4.7.1.166

herdProtect (fuzzy)
2015.6.14.13

IKARUS anti.virus
AdWare.BrowseFox
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.192.14761

Malwarebytes
PUP.Optional.JumpFlip.A
v2015.03.08.05

McAfee
Artemis!F58D5AFB0352
5600.6833

MicroWorld eScan
Adware.BrowseFox.BJ
16.0.0.495

NANO AntiVirus
Trojan.Win32.BPlug.dfogbn
0.30.0.64812

nProtect
Adware.BrowseFox.BJ
15.01.26.01

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Yontoo
15.3.8.5

Trend Micro House Call
TROJ_GEN.F0C2C00LH14
7.2.67

Vba32 AntiVirus
AdWare.MSIL.Agent
3.12.26.3

VIPRE Antivirus
Yontoo
37004

File size:
262.7 KB (269,040 bytes)

Product version:
1.0.0.7

Copyright:
(c) Round World. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\smy78df1\roundworld.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/10/2015 4:00:00 PM

Valid to:
1/11/2016 3:59:59 PM

Subject:
CN=Round World, O=Round World, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
1E6F69E3F386155D988683D665483D02

File PE Metadata
Compilation timestamp:
3/7/2015 2:08:39 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:Cyq7vzkKELk3SVaUs0FHxB+V9l63gY+GzGcEG+ZKTbRKaHdX4cEhBk:Cyq7v44SVcYHBth+ZcpnwBk

Entry address:
0xF515

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, EA, 7E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, C8, 21, 03, 10, E8, 4C, 02, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 4C, 77, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, C4, 93, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.0727

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file roundworld.dll has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Round World  by Yontoo Technology, Inc.
Round World is an adware program that installs as a web browser plugin to inject and display advertisements.
myroundworld.com/support
81% remove it
 
Powered by Should I Remove It?

The file roundworld.dll has been seen being distributed by the following 2 URLs.

Remove roundworld.dll - Powered by Reason Core Security