Cling Clang

Publisher Information

Cling Clang is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising. There is one additional code signing certificate issued to this publisher.
Remove Cling Clang Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
10/7/2013 2:00:00 AM

Valid to:
10/8/2014 1:59:59 AM

Subject:
CN=Cling Clang, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Cling Clang, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5d74fbb0061e5bd76029878075b12101

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Yontoo.ClingClang (M), PUP.Yontoo.ClingClang (M)
100.00%

Agnitum Outpost
Trojan.BPlug, PUA.Yotoon, PUA.Agent
12.00%

Trend Micro House Call
TROJ_SPNV.03J114, Suspicious_GEN.F47V0706, TROJ_GEN.F47V0330
12.00%

Dr.Web
Trojan.Yontoo.1816, Trojan.BPlug.123, Trojan.BPlug.28
12.00%

VIPRE Antivirus
Trojan.Win32.Generic, Yontoo
12.00%

McAfee Web Gateway
Artemis!PUP, Artemis!E1773805D7CA, Artemis!0B646E44D07F
12.00%

McAfee
Artemis!A7E9057E9977, Artemis!E1773805D7CA, Artemis!0B646E44D07F
12.00%

AVG
Cling, Focusbase, MalSign.Cling
12.00%

Jiangmin
AdWare/Yotoon.m, AdWare/Yotoon.l
10.00%

Panda Antivirus
Trj/CI.A, Adware/BrowserFox
10.00%

1 / 68      (Adware)
ClingClangBrowserFilter.exe  (163c6f49f2ad444cb6c4098524609825)

1 / 68      (Adware)
ClingClang.exe  (b501584dec391aa294818e870bc25c9a)

1 / 68      (Adware)
ClingClang.exe  (1458c034e7afd1a2196b1264f9704d48)

1 / 68      (Adware)
{1b646e65-56b2-4543-b72c-0e8976cf559e}gt.sys (StdLib)  (7147c0250cf42b9fb0afd42dc70cef88)

1 / 68      (Adware)
ClingClang.GCUpdate.dll  (811a27a46ceecb1946c4387026aa3672)

1 / 68      (Adware)
ClingClang.BrowserFilter.dll  (7b912e4f073c01351b4578f4901ebe61)

1 / 68      (Adware)
ClingClangBrowserFilter.exe  (9ea56f0d2526852137efb0f67db78b5b)

1 / 68      (Adware)
clingclang.browserfilter.helper.dll  (995ad58e404a9c06213f0adcd3472408)

1 / 68      (Adware)
updateclingclang.exe  (66badcf5676ca9055b4fce5a8c250e36)

1 / 68      (Adware)
ClingClang.BrowserAdapterS.dll  (ed8405d474886c9ccb4dfee66ca0e22a)

24 / 68    (Adware)
clingclangbho.dll (Cling Clang)  (e3e840225508abe2311b1e1bd99cb92f)

1 / 68      (Adware)
ClingClang.BRT.Helper.exe  (9f1167349c49d06cd87cd018a669efd6)

32 / 68    (Adware)
{1b646e65-56b2-4543-b72c-0e8976cf559e}w64.sys (StdLib)  (e3b1bb1314fc5dbe010aa83ba0903c36)

1 / 68      (Adware)
{1b646e65-56b2-4543-b72c-0e8976cf559e}t.sys (StdLib)  (f4be45e5fa222359542ea66357a1e656)

1 / 68      (Adware)
ClingClang.IEUpdate.dll  (dc6041fcc843f9689229c67022e00f07)

1 / 68      (Adware)
ClingClang.FFUpdate.dll  (234e1c2b18a4763f8329d42967c49344)

1 / 68      (Adware)
{1b646e65-56b2-4543-b72c-0e8976cf559e}t.sys (StdLib)  (95e5f403b0c19656f3c7a506257dfa24)

1 / 68      (Adware)
ClingClang.GCUpdate.dll  (ca875105b8f9a9586410a187fa7c6b95)

1 / 68      (Adware)
ClingClang.BrowserAdapterS.dll  (69c9858aa9f37eb8a05b1a02e18eb330)

1 / 68      (Adware)
ClingClang.IEUpdate.dll  (661fee5789874ba2075e4ce28d764b1b)

1 / 68      (Adware)
ClingClang.BrowserFilterG.dll  (8a768869b2702dd4d8f9421c1fdf44eb)

1 / 68      (Adware)
{1b646e65-56b2-4543-b72c-0e8976cf559e}t64.sys (StdLib)  (a5f29f35d5d6665ff2b9aa9389763817)

14 / 68    (Adware)
{1b646e65-56b2-4543-b72c-0e8976cf559e}w.sys (StdLib)  (aac6a146716a6a6464332cfbce4c88fd)

1 / 68      (Adware)
ClingClang.CompatibilityChecker.dll  (0d409cbee637725c57e97dedaf7ca5c1)

1 / 68      (Adware)
ClingClang.BRT.Helper.exe  (3eff5b4df2e68c990b4c231e381148a4)

1 / 68      (Adware)
ClingClang.BOASPRT.exe  (3f5230a3b34330ee05c706c693b4bcc0)

1 / 68      (Adware)
ClingClang.BOAS.exe  (e53571b9bba8da2649567e6b94c547fe)

1 / 68      (Adware)
wstlibg.sys (StdLib)  (9f1629d248e6be59aefa3bc0767a7326)

1 / 68      (Adware)
ClingClang.CompatibilityChecker.dll  (664543907fada1d8a102b2f9c3139018)

1 / 68      (Adware)
ClingClang.BrowserFilterG.dll  (b53ed3eb8893a3555de7951c01f8d871)

 
Latest 30 of 137 files

The following certificate is also signed by Cling Clang.

57FE01D1152E0C53CF4E777B39A50E10  (Sep 30, 2014 to Oct 31, 2015)

The following publishers (by Authenticode signature organization name) are related.

30 of 89 publishers

Remove Cling Clang Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Cling Clang by VeriSign, Inc. on October 07, 2013 with the serial number '5d74fbb0061e5bd76029878075b12101'.