BuzzSearch

Publisher Information

BuzzSearch is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising. Thre are 2 additional code signing certificates issued to this publisher.
Remove BuzzSearch Malware - Powered by Reason Core Security
Authority:
COMODO CA Limited

Valid from:
5/3/2014 2:00:00 AM

Valid to:
5/4/2015 1:59:59 AM

Subject:
CN=BuzzSearch, OU=BuzzSearch, O=BuzzSearch, STREET=10620 Treena Street Suite 230, L=San Diego, S=Ca, PostalCode=92131, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00dd9fcb2e901e39fd097f0632d190af7e

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Yontoo.BuzzSearch (M), Adware.Yontoo.BuzzSearch (M)
100.00%

VIPRE Antivirus
Yontoo, Threat.4150696, Trojan.Win32.Generic
30.00%

Baidu Antivirus
Adware.Win64.BrowseFox, Adware.Win32.BrowseFox
30.00%

AVG
Adware Generic_r, Brewurst, MalSign.Slizearch, Buzzeach
30.00%

Trend Micro House Call
Suspicious_GEN.F47V0917, TROJ_GEN.F47V0604, TROJ_GEN.F0C2C00LI14, Suspicious_GEN.F47V0624
28.00%

McAfee Web Gateway
Artemis, Artemis!5292CBCCFAC4, BehavesLike.Win32.BrowseFox.dh, Artemis!7AE07034A137
28.00%

McAfee
Program.BrowseFox.e, Artemis!5292CBCCFAC4, Artemis!7AE07034A137
28.00%

MicroWorld eScan
Adware.SwiftBrowse.AQ
26.00%

nProtect
Adware.SwiftBrowse.AQ
26.00%

Agnitum Outpost
Trojan.BPlug, PUA.Agent, PUA.Yotoon
26.00%

8 / 68      (Adware)
{ba099a85-e825-4802-83e7-d386a5b4a734}t.sys (StdLib)  (81d661f63ce670649d92de39c3f783aa)

1 / 68      (Adware)
BuzzSearch.BrowserAdapterS.dll  (9d0d23697de563decc4afe9b85d3a017)

33 / 68    (Adware)

43 / 68    (Adware)

1 / 68      (Adware)
ba099a85e825480283e764.dll  (9134a22f576f278d707a13d6049ad082)

1 / 68      (Adware)
ba099a85e825480283e7.dll  (92ea287efc7605f7f2d64e95d72f96a3)

1 / 68      (Adware)
updatebuzzsearch.exe  (3a000b1db12dad195cfb1fa31b0edfe8)

8 / 68      (Adware)
{ba099a85-e825-4802-83e7-d386a5b4a734}t.sys (StdLib)  (4cc944bab2dcd0628c1a2ebe12dc3027)

33 / 68    (Adware)

1 / 68      (Adware)
ba099a85e825480283e764.dll  (5622d8c31852f1c08ca32071877e67ba)

1 / 68      (Adware)
ba099a85e825480283e7.dll  (68e3f23a017a570e47f30496e12c1f60)

1 / 68      (Adware)
buzzsearchbho.dll (BuzzSearch)  (4c9c06717b167e86d2f61a7e4687986e)

1 / 68      (Adware)
BuzzSearch.CompatibilityChecker.dll  (56cd2b6ad1d7b50960bc4cf1bbeecc8f)

1 / 68      (Adware)
BuzzSearch.BrowserAdapterS.dll  (b2ffe9a6f5e2ff29bce64ea23555293f)

1 / 68      (Adware)
updatebuzzsearch.exe  (63b56c67ea52b22a616b4dfd15fbbb62)

1 / 68      (Adware)
utilbuzzsearch.exe  (e0a7700b52627105b7445083e74782dd)

21 / 68    (Adware)
{ba099a85-e825-4802-83e7-d386a5b4a734}w.sys (StdLib)  (0c0bb1ef13159eb1f202bfb9d91a84f8)

1 / 68      (Adware)
{ba099a85-e825-4802-83e7-d386a5b4a734}gw.sys (StdLib)  (997ab08f1d5a4540e55d67a91708fd46)

1 / 68      (Adware)
BuzzSearch.FeSvc.dll  (537cfedd4b12d924362ee6ecedf86ab3)

1 / 68      (Adware)
buzzsearchbho.dll (BuzzSearch)  (73812d08427c015dcf94b92c7c737b2e)

1 / 68      (Adware)
ba099a85e825480283e7.dll  (cd36f3c196fbafe091b7d07047fe2964)

1 / 68      (Adware)
BuzzSearch.exe  (ebf1f97900947cfe0a2aec282c7a7f49)

1 / 68      (Adware)
BuzzSearch.exe  (338a4321cf613dd02bc19af8c6231cca)

23 / 68    (Adware)
{ba099a85-e825-4802-83e7-d386a5b4a734}w64.sys (StdLib)  (a1f706ef893aec7de775221a2ee5bc53)

43 / 68    (Adware)

1 / 68      (Adware)
buzzsearchbaapp.dll  (78240fcb99a434d3b57f03fb3ce5a683)

1 / 68      (Adware)
buzzsearch.browseradapter.exe  (9f97683891e7370cd33fa908abbd35f1)

33 / 68    (Adware)

1 / 68      (Adware)
ba099a85e825480283e764.dll  (8a46302523d7c7b79ad43facefa3d7fb)

1 / 68      (Adware)
ba099a85e825480283e7.dll  (44fa40e495744ecd3c6e2ac9b2b5034b)

 
Latest 30 of 214 files

The certificates below are also signed by BuzzSearch.

39CF7BDCF992CEB4BEF0448204CEA1D1  (Nov 04, 2014 to Dec 04, 2015)

04E8478F4E7A77520D661585F56C13E0  (Nov 07, 2013 to Nov 08, 2014)

The following publishers (by Authenticode signature organization name) are related.

30 of 194 publishers

Remove BuzzSearch Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to BuzzSearch by COMODO CA Limited on May 03, 2014 with the serial number '00dd9fcb2e901e39fd097f0632d190af7e'.