zombiealert.a222801bb6b4.2.6.80.dll

Creative Island Media, LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module zombiealert.a222801bb6b4.2.6.80.dll by Creative Island Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Creative Island Media, LLC  (signed and verified)

MD5:
8ed50aed55b1286d21b6b619483f6a82

SHA-1:
8e1a668087771c7fb1375e6d31e627f0f924ea92

SHA-256:
6ef3d3eab3e82e508e3df3e7fb8529c8c1b5559f4b6caa660bec07ca3098b150

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 4:13:47 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
16.8.16.17

File size:
1.3 MB (1,356,664 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Windows\System32\zombiealert.a222801bb6b4.2.6.80.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/23/2014 9:00:00 PM

Valid to:
6/23/2015 8:59:59 PM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0ED42A15C608C5CB28B1EF56CE392E5E

File PE Metadata
Compilation timestamp:
4/28/2014 3:34:28 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:/Yjp4gfY2twwnERaB0ru0Zyi6r+/V9RsVYZJTTaSe+v:/YjpffY2tjgu0ZD98YTT1B

Entry address:
0xC1B10

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 9F, D7, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83, F8, 40, 72, 1E, 48, F7, D9, 83, E1, 07, 74, 06, 4C, 2B, C1, 48, 89, 10, 48, 03...
 
[+]

Code size:
882.5 KB (903,680 bytes)

Remove zombiealert.a222801bb6b4.2.6.80.dll - Powered by Reason Core Security