secretsauce.browseradapter.exe

secretsauce

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application secretsauce.browseradapter.exe by secretsauce has been detected as adware by 27 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
secretsauce  (signed and verified)

MD5:
3f1dfef4902feb539bcc21bcb49aa12e

SHA-1:
468094ec8a7d7fcd864033ed03be544e9806d39e

SHA-256:
1f46e509cb0a144b7f95deb00ee4217f56fe4c38e3bd48e6bf860998a9839444

Scanner detections:
27 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/27/2024 11:02:30 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.BB
5594902

Agnitum Outpost
Trojan.Yontoo
7.1.1

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.05.10

avast!
Win32:BrowseFox-HQ [PUP]
150414-0

AVG
Adware AdPlugin.DML
2014.0.4311

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15515

Bitdefender
Adware.BrowseFox.BB
1.0.20.675

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Adware.Swiftbrowse-1369
0.98/20464

Comodo Security
Application.Win32.BrowseFox.AKM
22127

Dr.Web
Trojan.Yontoo.1734
9.0.1.0135

Emsisoft Anti-Malware
Adware.BrowseFox.BB
10.0.0.5366

ESET NOD32
Win32/BrowseFox.AX potentially unwanted
9.11633

F-Prot
W32/S-a777f78c
v6.4.7.1.166

F-Secure
Adware.BrowseFox.BB
11.2015-15-05_6

G Data
Adware.BrowseFox.BB
15.5.25

herdProtect (fuzzy)
2015.8.12.15

K7 AntiVirus
Adware
13.203.15857

MicroWorld eScan
Adware.BrowseFox.BB
16.0.0.405

NANO AntiVirus
Trojan.Win32.Yontoo.dqyaqf
0.30.24.1357

nProtect
Adware.BrowseFox.BB
15.05.15.01

Quick Heal
PUA.Secretsauc.Gen
5.15.14.00

Reason Heuristics
Threat.Yontoo.secretsauce
15.5.15.14

Rising Antivirus
PE:Adware.SwiftBrowse!6.1A2E
23.00.65.15513

Vba32 AntiVirus
AdWare.MSIL.Agent
3.12.26.4

VIPRE Antivirus
Threat.4741131
39486

Zillya! Antivirus
Adware.Agent.Win32.56110
2.0.0.2173

File size:
105.7 KB (108,272 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\secretsauce\bin\secretsauce.browseradapter.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/30/2014 3:00:00 AM

Valid to:
10/31/2015 1:59:59 AM

Subject:
CN=secretsauce, O=secretsauce, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
58483913E0DBCAAB64CC87477F31A66E

File PE Metadata
Compilation timestamp:
5/15/2015 10:34:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:1kia8A7QPno105F3emHt7bu26Gf3p/ekGVn8Bxbx+iW1T:1kia85W05FLN7yDOVxxbx+iWF

Entry address:
0x4BD5

Entry point:
E8, D5, 21, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 5D, E9, 03, 06, 00, 00, 3B, 0D, 70, 60, 41, 00, 75, 02, F3, C3, E9, 51, 22, 00, 00, 8B, FF, 55, 8B, EC, 83, EC, 10, EB, 0D, FF, 75, 08, E8, 54, 23, 00, 00, 59, 85, C0, 74, 0F, FF, 75, 08, E8, 9A, 07, 00, 00, 59, 85, C0, 74, E6, C9, C3, F6, 05, 38, 75, 41, 00, 01, BF, 2C, 75, 41, 00, BE, 5C, 22, 41, 00, 75, 2C, 83, 0D, 38, 75, 41, 00, 01, 6A, 01, 8D, 45, FC, 50, 8B, CF, C7, 45, FC, 64, 22, 41, 00, E8, 2C, 00, 00, 00, 68, 7E, 1E, 41, 00, 89, 35, 2C...
 
[+]

Code size:
68 KB (69,632 bytes)

Remove secretsauce.browseradapter.exe - Powered by Reason Core Security