Special Box

Publisher Information

Special Box is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising.
Authority:
VeriSign, Inc.

Valid from:
2/23/2015 1:00:00 AM

Valid to:
2/24/2016 12:59:59 AM

Subject:
CN=Special Box, O=Special Box, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68f233dc671bbe554282d38dfeb31c19

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Yontoo (M), Adware.Yontoo (M)
100.00%

1 / 68      (Adware)
{2fbd7dfe-a573-4ffa-a5f6-c8e79be0e000}gt64.sys (StdLib)  (c014467a23e1a28e2f1a6117aa2cdfbf)

1 / 68      (Adware)
{20da0614-35ac-464d-8200-eee5dbb17760}gt.sys (StdLib)  (151a319f8b9dd34daa39574377624cfd)

1 / 68      (Adware)
specialbox.expext.dll  (e6ed880877dd262d2ee9b10e746cd65f)

1 / 68      (Adware)
specialbox.browseradapter64.exe  (d95ba8ee18f33c35a93a066e1cee8121)

1 / 68      (Adware)
appmgr.bak  (724061e6b7639319a6c69e562c6f20ae)

1 / 68      (Adware)
maintainer.bak  (fe5d8a48875b0d26e979768f5a53c700)

1 / 68      (Adware)
specialbox.purbrowseg.dll  (1e45d5ff7f6075eaf96921bde65e7717)

1 / 68      (Adware)
specialbox.gcupdate.dll  (c471996c22adc62cc13460b486b49464)

1 / 68      (Adware)
specialbox.findlib.dll  (0e84bf96d8441204bf19636c71838325)

1 / 68      (Adware)
specialbox.ffupdate.dll  (7f7a170cef5ef38143dbc6944469723e)

1 / 68      (Adware)
specialbox.expext.dll  (81d52bd1606e645fb8e4ccbf488135f0)

1 / 68      (Adware)
specialbox.compatibilitychecker.dll  (c0229f62f91bd1351e0a840ee709c291)

1 / 68      (Adware)
specialbox.browseradapter.dll  (a47c8353c260ea1b20a58016e79ebacd)

1 / 68      (Adware)
specialbox.purbrowse.exe  (3e3b522d5c556d5fd2c47416d50e8cc8)

1 / 68      (Adware)
specialbox.browseradapter64.exe  (d143bb87920062a1d69182e432725567)

1 / 68      (Adware)
specialbox.browseradapter.exe  (c7b7f94b2195455fa0cb72bdb41ea710)

1 / 68      (Adware)
20da64.dll (by TODO: <Company name>)  (88f8d738700d353b1ab2f084d05f68c8)

1 / 68      (Adware)
20da06143564.dll  (d3b4cc1eb3427a90409129204aa46447)

1 / 68      (Adware)
20da061435.dll  (e006d657c3a0943032099ce91d3de9ff)

1 / 68      (Adware)
specialboxun.exe  (5df3cf8617e490131738441422c5bc7b)

1 / 68      (Adware)
{20da0614-35ac-464d-8200-eee5dbb17760}w.sys (StdLib)  (47372565c0f71097f843e030bdca65a7)

1 / 68      (Adware)
specialbox.purbrowse64.exe  (7c56a10a915cd414474dc4e7cc7747f4)

1 / 68      (Adware)
trze71b.tmp  (3ab07f9d0243d3579d8290b2dffe073d)

1 / 68      (Adware)
trza72d.tmp  (60c75520c44fee9ae15ef0b6101fd4b6)

1 / 68      (Adware)
trz9517.tmp  (c8a46c2c304bee8b37338a2630ee3c40)

1 / 68      (Adware)
trz8889.tmp  (9c99c7a697fa4e355dc7d72be5b6607a)

1 / 68      (Adware)
trz72b5.tmp  (631bfc1a59f0c6f055aa17f6ebb588fc)

1 / 68      (Adware)
trz3145.tmp  (801eb2e6ab93ac446c513fccbb25d65c)

1 / 68      (Adware)
trz2ca7.tmp  (3062ca3ee2f7fe8dfe3c39b3b1e7133d)

1 / 68      (Adware)
trz29dc.tmp  (4c34f3253ab41be7b0604e39836ccb08)

 
Latest 30 of 7,362 files

The following publishers (by Authenticode signature organization name) are related.

30 of 141 publishers

* Note, the details and description above are based on the code signing digital signature issued to Special Box by VeriSign, Inc. on February 23, 2015 with the serial number '68f233dc671bbe554282d38dfeb31c19'.