Rolimno

Publisher Information

Rolimno is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising.
Remove Rolimno Malware - Powered by Reason Core Security
Authority:
VeriSign, Inc.

Valid from:
8/12/2013 7:00:00 PM

Valid to:
8/13/2015 6:59:59 PM

Subject:
CN=Rolimno, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Rolimno, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0d2645238961d2084208fc4b5b89e7fd

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Yontoo.Rolimno.Installer (M), PUP.Yontoo.Rolimno (M), Adware.Yontoo.Rolimno (M)
100.00%

VIPRE Antivirus
Trojan.Win32.Generic, Threat.4150696, Yontoo
14.00%

Emsisoft Anti-Malware
Adware.NetFilter, Adware.BrowseFox.BR, Adware.SwiftBrowse.CH
14.00%

Clam AntiVirus
Win.Adware.Swiftbrowse-75, Win.Adware.Mplug-43, Win.Adware.Swiftbrowse-497, Win.Adware.Swiftbrowse-330
14.00%

Sophos
BrowseSmart, PUA 'BrowseSmart' (of type Adware), PUA 'Browse Fox', PUA 'Rolimno' (of type Adware)
14.00%

AVG
Rolimno, GreyGray
14.00%

MicroWorld eScan
Adware.SwiftBrowse.S, Adware.BrowseFox.BR, Adware.SwiftBrowse.CH
12.00%

nProtect
Adware.SwiftBrowse.S, Adware.BrowseFox.BR, Adware.SwiftBrowse.CH
12.00%

Zillya! Antivirus
Adware.Yotoon.Win64.3, Backdoor.PePatch.Win32.42822, Adware.Yotoon.Win64.14, Adware.SwiftBrowse.Win64.1
12.00%

F-Prot
W64/A-e967bae2, W32/A-d34eca05, W64/A-59c9c70a, W64/S-6dc29f50
12.00%

1 / 68      (Adware)
rolimnobho.dll (Rolimno)  (26dd9dc80e40512ba78f927ce77063e9)

1 / 68      (Adware)
Rolimno.exe  (b0c52f0add8daa398bbd87d72bcafd1e)

1 / 68      (Adware)
Rolimno.exe  (38f8c9fa1c2a749d8cc9349bf1c3ade0)

1 / 68      (Adware)
maintainer.bak  (d84bcbcc9e95ce9fddcb646eeaaee9a4)

20 / 68    (Adware)
{234280f6-0eca-4130-85e8-3d4370f3360b}w64.sys (StdLib)  (b523c2bec262228e9166645bfb808f31)

27 / 68    (Adware)

35 / 68    (Adware)

1 / 68      (Adware)
Rolimno.exe  (6ce466aa4f93a402157882254e10fd3b)

1 / 68      (Adware)
e4c6227e782d4fb99a9164.dll  (04070e80cd52a9931baee43486a9b514)

1 / 68      (Adware)
e4c6227e782d4fb99a91.dll  (72f04f50830124ea37fcf6b27dc72a76)

1 / 68      (Adware)
rolimnobho.dll (Rolimno)  (d1cc88c93b4e5a8c364f2d63036afc55)

20 / 68    (Adware)
{234280f6-0eca-4130-85e8-3d4370f3360b}w64.sys (StdLib)  (5dcee662fbc570e2e214e6cc12b91cfd)

1 / 68      (Adware)
Rolimno.PurBrowse.dll  (56a8fa3f923d28f3686ab2c288b9c922)

1 / 68      (Adware)
Rolimno.BrowserAdapterS.dll  (5c2e7ba055dcdb2705d673a691d212b0)

35 / 68    (Adware)

1 / 68      (Adware)
rolimnobaapp.dll  (f0e8595e34cf081221ff1302819bc999)

1 / 68      (Adware)
rolimno.purbrowse64.exe  (3fdea46b776981725c8392bee2470796)

1 / 68      (Adware)
rolimno.browseradapter.exe  (37d817b1121fc1edadf54ce83a1337c3)

1 / 68      (Adware)
updaterolimno.exe  (1b6d4e09ee6c937eedf36cb1ece29155)

1 / 68      (Adware)
{e4c6227e-782d-4fb9-9a91-19df3596a980}t64.sys (StdLib)  (2b87195499d62f7ee517a5fd6584ef4f)

1 / 68      (Adware)
{e4c6227e-782d-4fb9-9a91-19df3596a980}gw.sys (StdLib)  (d893c344cf890421834c166142f47865)

1 / 68      (Adware)
Rolimno.CompatibilityChecker.dll  (e25cda55c450844fd18ef8c44a6064ed)

1 / 68      (Adware)
Rolimno.BrowserAdapterS.dll  (2c50e4297882b3eeb7d1f64b54ae3be8)

15 / 68    (Adware)
{e4c6227e-782d-4fb9-9a91-19df3596a980}gw64.sys (StdLib)  (05ad20fbc4165176997f9534ca220801)

1 / 68      (Adware)
{dfe2550a-bc38-40d2-a94b-22760bae1c54}gw64.sys (StdLib)  (f13b653e9069f003a29b2d2f68ceba3b)

1 / 68      (Adware)
{234280f6-0eca-4130-85e8-3d4370f3360b}gw64.sys (StdLib)  (06ad4a3deef3b9d08245af83fd91c9c5)

1 / 68      (Adware)
{e4c6227e-782d-4fb9-9a91-19df3596a980}gw64.sys (StdLib)  (0dee281a745bef024d9f73a57a1af737)

1 / 68      (Adware)
{d5addb71-db13-419d-aa7f-1053471a2509}gw64.sys (StdLib)  (31e9a2f3875bb3375c71fada26ae6bdb)

1 / 68      (Adware)
{234280f6-0eca-4130-85e8-3d4370f3360b}gw64.sys (StdLib)  (3c86e61aaacf3c3f2787ac77c3bb1f3c)

1 / 68      (Adware)
{dfe2550a-bc38-40d2-a94b-22760bae1c54}w64.sys (StdLib)  (daaff2d65a058c7910f30b8e5e5fb6ba)

 
Latest 30 of 259 files

The following publishers (by Authenticode signature organization name) are related.

30 of 146 publishers

Remove Rolimno Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Rolimno by VeriSign, Inc. on August 12, 2013 with the serial number '0d2645238961d2084208fc4b5b89e7fd'.