surfslide.dll

surf slide

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module surfslide.dll by surf slide has been detected as adware by 13 anti-malware scanners. This file is typically installed with the program surf slide by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. It is also typically executed from an Internet Explorer cache folder. The file has been seen being downloaded from install-cdn.surfslidetide.com.
Publisher:
surf slide  (signed and verified)

Product:
surf slide

Version:
1.0.0.6

MD5:
cd9a5b470f83d4800da21e1877a306da

SHA-1:
0d49a8a6132c8475a37d4a0ddc663825e01d0456

SHA-256:
6d75500056acf4fdf5438ae2cb01e1da1dd1457c4716cd7f5eb58f522b6e7a4c

Scanner detections:
13 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/29/2024 6:27:36 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.197.26

avast!
Win32:BrowseFox-ER [PUP]
2014.9-141229

AVG
BrowseFox.F
2015.0.3246

Comodo Security
Application.Win32.BrowseFox.JM
20436

Dr.Web
Trojan.BPlug.215
9.0.1.0363

ESET NOD32
Win32/BrowseFox (variant)
8.10912

Fortinet FortiGate
Riskware/BrowseFox
12/29/2014

K7 AntiVirus
Trojan
13.188.14395

Malwarebytes
PUP.Optional.SurfSlide.A
v2014.12.29.10

McAfee
Artemis!CD9A5B470F83
5600.6902

NANO AntiVirus
Riskware.Win32.Kranet.dkvuxq
0.28.6.64267

Reason Heuristics
PUP.surfslide.J
14.12.29.10

Vba32 AntiVirus
AdWare.SwiftBrowse
3.12.26.3

File size:
244.2 KB (250,096 bytes)

Product version:
1.0.0.6

Copyright:
(c) surf slide. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\surfslide.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2014 4:00:00 AM

Valid to:
9/3/2015 3:59:59 AM

Subject:
CN=surf slide, O=surf slide, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
40C4725F1712C4789A4BDCEA560D5BE2

File PE Metadata
Compilation timestamp:
12/20/2014 6:31:10 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:hc55ohXqiQAio8glKXt6SSkFhTwGMuDTci+nIaIUVbyjz1qA:hRDQAiokXtDSuAImujz1qA

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 80, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 04, 78, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 0C, A5, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file surfslide.dll has been discovered within the following programs.

surf slide  by Yontoo Technology, Inc.
SurfSlideTide is a web browser extension that injects display advertising in the user's browser. Ads are displayed in the form of banners and contextual text-links and are both injected in white space areas of the HTML page or over existing ads of the underlying web site.
surfslidetide.com/support
87% remove it
 
Powered by Should I Remove It?

The file surfslide.dll has been seen being distributed by the following URL.

Remove surfslide.dll - Powered by Reason Core Security