Air Globe

Publisher Information

Air Globe is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising.
Authority:
VeriSign, Inc.

Valid from:
1/10/2015 12:00:00 PM

Valid to:
1/11/2016 11:59:59 AM

Subject:
CN=Air Globe, O=Air Globe, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0c68efa725db8110ce807489dac03553

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Yontoo (M), PUP.Yontoo (M)
100.00%

1 / 68      (Adware)
airglobeuninstall.exe  (0fef80f7cd67f4756c6253feaa0d599c)

1 / 68      (Adware)
plugin.exe  (6a0543e34e28fe523a811398048cea4f)

1 / 68      (Adware)
{0c1bfd68-2f89-48f3-b055-985cab8bbde5}gw.sys (StdLib)  (e6251f884e3dc6208e02514dd2a5ab9f)

1 / 68      (Adware)
{0c1bfd68-2f89-48f3-b055-985cab8bbde5}w64.sys (StdLib)  (2e087e869699da2339bf931422f99023)

1 / 68      (Adware)
appmgr.exe  (61b7fa33c86572f34673c4778b5a8fec)

1 / 68      (Adware)
cytiweb.repmon.dll  (922da272b5d295cc49c5367cc219a88d)

1 / 68      (Adware)
cytiweb.purbrowse.dll  (621e067be950110d982959d4392f01fd)

1 / 68      (Adware)
cytiweb.gcupdate.dll  (3f214474cf30091c347817e566fdd58c)

1 / 68      (Adware)
cytiweb.findlib.dll  (0716aa0b567ffb3e78a1645280b4a145)

1 / 68      (Adware)
cytiweb.ffupdate.dll  (6542c3b579eead76a01715c8e31d0f43)

1 / 68      (Adware)
cytiweb.expext.dll  (671fdedff7a72870cae7baf9c0c569d0)

1 / 68      (Adware)
cytiweb.browseradapter.dll  (442610e2f4fc4d42181f47e53b4efe4c)

1 / 68      (Adware)
cytiweb.purbrowse.exe  (8294ef68f8ad4537ef532bdf807a4c22)

1 / 68      (Adware)
cytiweb.expext.exe  (06b41f8463f0861d31310ccfe3d4fe31)

1 / 68      (Adware)
cytiweb.browseradapter64.exe  (596daeeb0d940dcbcc5775de4816f7be)

1 / 68      (Adware)
cytiweb.browseradapter.exe  (16a8c97c38c9b8a1d01e9db0d2e192cb)

1 / 68      (Adware)
09c3ffd6f164.dll  (b16d449463258d836156791f38eb4dee)

1 / 68      (Adware)
09c3ffd6f1.dll  (b9275cc53782a35680e0e8801159c1a4)

1 / 68      (Adware)
09c364.dll (by TODO: <Company name>)  (e35ef11cbff2492336760c02ba99cd93)

1 / 68      (Adware)
09c3.dll (by TODO: <Company name>)  (56e1d21e07de711156a4e617e4a5dc16)

1 / 68      (Adware)
cytiweb.expext.exe  (1b21a5b0762df94b483c7ca98982deb7)

1 / 68      (Adware)
cytiweb.browseradapter64.exe  (6ab21540517673bda303ec9dbf0a5f0d)

1 / 68      (Adware)
cytiweb.browseradapter.exe  (9e34d6ad5049629dcac9d0a3fd717f5d)

1 / 68      (Adware)
09c3ffd6f164.dll  (506812429e4e5a61bee5b5e0a757c40b)

1 / 68      (Adware)
09c3ffd6f1.dll  (60600f4c75457b016ffc09d1ada79c71)

1 / 68      (Adware)
09c364.dll (by TODO: <Company name>)  (babac7786359c878c7a2b7f71ad8ab46)

1 / 68      (Adware)
09c3.dll (by TODO: <Company name>)  (ee109718d50cc156f48c6e4f6edbb389)

1 / 68      (Adware)
{74451d56-bbfc-4253-a8d1-124e908a85a4}gw64.sys (StdLib)  (a8135df75ac6f556bde2c3eda67f66cb)

1 / 68      (Adware)
{45e43145-d77e-4e5e-b7ef-6236a72c1378}t.sys (StdLib)  (ab1c5d09a3167247bdbcc28293d4bffa)

1 / 68      (Adware)
plugin.exe  (a355f4840a0b4651bdd469e7cfb5b629)

 
Latest 30 of 24,994 files

The following publishers (by Authenticode signature organization name) are related.

30 of 183 publishers

* Note, the details and description above are based on the code signing digital signature issued to Air Globe by VeriSign, Inc. on January 10, 2015 with the serial number '0c68efa725db8110ce807489dac03553'.