Dollar Dream

Publisher Information

Dollar Dream is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising.
Authority:
VeriSign, Inc.

Valid from:
1/14/2015 7:00:00 PM

Valid to:
1/15/2016 6:59:59 PM

Subject:
CN=Dollar Dream, O=Dollar Dream, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4f1fad042e21f99920eb8bc152dbceb0

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
Adware.Yontoo.DollarDream, PUP.Yontoo.DollarDream, PUP.Yontoo.Installer, PUP.Yontoo.DollarDream (M), Adware.Yontoo.DollarDream (M), PUP.Yontoo.DollarDream.Installer (M), PUP.Yontoo.DollarDr (M), PUP.Yontoo.DollarDr.Installer (M), PUP.Yontoo (M)
100.00%

F-Prot
W32/S-3e9914e7, W32/S-a777f78c, W32/MegaBrowse.A, W32/S-4dc21c6d, W32/S-a7161e1c, W32/A-248e95ab, W32/S-f64f6ec1, W32/S-de5f2e52
38.00%

Dr.Web
Trojan.Yontoo.1768, Trojan.BPlug.979, Trojan.BPlug.891, Trojan.Yontoo.1734, hacktool program Tool.NetFilter.313, Trojan.Yontoo.1016, infected with Trojan.Siggen6.33539
34.00%

ESET NOD32
Win64/BrowseFox.CJ potentially unwanted application, Win32/BrowseFox.AC potentially unwanted application, Win32/BrowseFox.M potentially unwanted application, MSIL/BrowseFox.G potentially unwanted application, MSIL/BrowseFox.H potentially unwanted application
34.00%

K7 AntiVirus
Trojan , Adware , Riskware , Unwanted-Program
32.00%

Avira AntiVirus
ADWARE/BrowseFox.Gen7, Adware/BrowseFox.A.1227, ADWARE/BrowseFox.Gen4
32.00%

herdProtect (fuzzy)
a variant of bcaf8c84a24e3a1149ed98946499dc6da817ceb0, a variant of 9d16213a1ff71b4fc6edf7c564649a4b3bd0e804, a variant of 9bcd1b1c7a27befd3ba41a2f5f07fb94de01a96a
30.00%

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.173093, Adware.BrowseFox.AG, Adware.BrowseFox.BU, Adware.SwiftBrowse.CY, Adware.BrowseFox.V, Gen:Variant.Mikey.11547, Gen:Variant.Adware.SwiftBrowse
28.00%

NANO AntiVirus
Riskware.Win32.SwiftBrowse.dodrvj, Riskware.Win32.Agent.dqnjuw, Trojan.Win32.BPlug.dmjqza, Trojan.Win32.BPlug.dnpvno, Trojan.Win32.Yontoo.dnkubo
28.00%

AhnLab V3 Security
PUP/Win32.BrowseFox
28.00%

1 / 68      (Adware)
appmgr.bak  (b2813fec04beea92e02651e226ce72d2)

1 / 68      (Adware)
{aa0e2a76-3e80-498c-8e55-9ed2435284a0}w.sys (StdLib)  (538c5cb6b3121260df0b70ace62785c9)

1 / 68      (Adware)
{aa0e2a76-3e80-498c-8e55-9ed2435284a0}gw.sys (StdLib)  (b666d03fe5a71af79e281fde50632f0d)

1 / 68      (Adware)
dollardream82.exe  (da74593fbb6619af57cfdcd725ecc3f1)

1 / 68      (Adware)
{40ef89ae-1972-44f6-b6ef-0302038edc83}gt.sys (StdLib)  (4ecdb3be8e1526eae87929fda4da18d7)

1 / 68      (Adware)
{ed4e53c0-1dd5-45f5-a4aa-1bc30f315de4}gw64.sys (StdLib)  (bb36cd88191a2534fd18d363eb2e3b7d)

1 / 68      (Adware)
dollardream82.exe  (c1b7fe60b3ef3fb105afe5c8d84af690)

1 / 68      (Adware)
utildollardream.exe  (8e5ddc9de7cdc75528209124cd3d5b23)

1 / 68      (Adware)
dollardreamuninstall.exe  (b81cd92b8883e4fdf47c3f7868dd72d8)

1 / 68      (Adware)
dollardreambho.dll (Dollar Dream)  (9c58cb7a2ef225afe9118b8201ed21b5)

1 / 68      (Adware)
dl  (9d71840f35c2c30cbb137e1eec2b11f5)

1 / 68      (Adware)
appmgr.bak  (cc3b6c75c33c330ceb6ba138172b5244)

1 / 68      (Adware)
dollardream.purbrowse64.exe  (14f64c22f167e5610953bd6352d28968)

1 / 68      (Adware)
dollardream.expextdll.dll  (a2a3b94e4c302ce437467d754b3b6fc6)

1 / 68      (Adware)
dollardream.expext.exe  (ff366fd077fcdadbc2b954de420d208c)

1 / 68      (Adware)
dollardream.browseradapter64.exe  (c54be8cfa5e9e866135ff5b19b4255f5)

1 / 68      (Adware)
dollardream.browseradapter.exe  (6fa334df72579e20cf02f8a3dcb20c0e)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
450926dfa93045be88e164.dll  (fdb78c0b5e30ea6e0b511fdc87a82df8)

1 / 68      (Adware)
450926dfa93045be88e1.dll  (15a7c14f6332191534223da8585332a3)

1 / 68      (Adware)
updatedollardream.exe  (f9a9b122f9fe93598b8b643c8b49dc71)

1 / 68      (Adware)
dollardreamuninstall.exe  (25040f8dc25d83972d585a8365b09f54)

1 / 68      (Adware)
dollardreambho.dll (Dollar Dream)  (2ad9f114f3be7c83902dba90b370728d)

1 / 68      (Adware)
plugin.exe  (ffe4203476d6099fe66f1eedccb0ea7c)

1 / 68      (Adware)
dl  (c23c96e15b703bc4403468c8af9dc50b)

1 / 68      (Adware)
appmgr.bak  (e3460d8f3a49647b0a4d8a326efb9602)

10 / 68    (Adware)
dollardream.purbrowseg.dll  (11a48139d5df8584677bd84e1d3769c6)

3 / 68      (Adware)
dollardream.gcupdate.dll  (0b250e1b70947a8eabf710229afd0e26)

7 / 68      (Adware)
dollardream.ffupdate.dll  (cf81611a7b97f81edb5f8dba0f99f460)

 
Latest 30 of 52 files

The following publishers (by Authenticode signature organization name) are related.

30 of 66 publishers

* Note, the details and description above are based on the code signing digital signature issued to Dollar Dream by VeriSign, Inc. on January 14, 2015 with the serial number '4f1fad042e21f99920eb8bc152dbceb0'.