thirteen degrees

Publisher Information

thirteen degrees is a brand of the Sambreel/Yontoo group, a web advertising company located in Carlsbad, CA. The company is a primary distributor of unwanted software. It is part of the Yontoo/Sambreel group and distributes web browser add-ons, typically potentially unwanted and adware in nature, that are designed to modify a user's typical search beahvior as well as display context and popup advertising.
Authority:
VeriSign, Inc.

Valid from:
4/30/2015 3:00:00 AM

Valid to:
4/30/2016 2:59:59 AM

Subject:
CN=thirteen degrees, O=thirteen degrees, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7ec505cb2a21f49edc7f06fd1e77efc8

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Yontoo (M), Adware.Yontoo (M)
100.00%

1 / 68      (Adware)
thirteendegrees.purbrowse.exe.tmp  (fbd2a47e2633c133b5350cf9008e4acd)

1 / 68      (Adware)
ic-0.36579165f226d4.exe  (dbdcd80b86a3bffe6cebef2db1ab1100)

1 / 68      (Adware)
{4dbd9344-ba73-4a75-90f4-f5f310ce530b}gw64.sys (StdLib)  (da8e5fde83681181af32bcb0b01e6983)

1 / 68      (Adware)
thirteendegreesun.exe  (3a1bcac549c66610b5f22f1ae7b0945e)

1 / 68      (Adware)
{de4877ac-5fd3-4d90-9546-7d4fb5cf174e}gw.sys (StdLib)  (0be25c6ad31adcf46b7e635e5e1eab84)

1 / 68      (Adware)
{d87b5d62-2739-4f0c-818c-3a9d867bfbcf}gw.sys (StdLib)  (a7626182618d23ede0ccb61f873638ad)

1 / 68      (Adware)
{b561d2b1-2f9b-4386-91a4-9784a0f6745a}gw.sys (StdLib)  (c456b709a7bed3c2de6887e278e21ef5)

1 / 68      (Adware)
{0788ea6f-3628-4929-9d8c-0755c0b34f78}gw.sys (StdLib)  (a3563c196ebd8eda638c62e450b16e24)

1 / 68      (Adware)
{fff0f003-d589-4117-a4ef-d46ac4f8f083}gw.sys (StdLib)  (98fb0c1e40b0df82fd85c05a96ab2118)

1 / 68      (Adware)
appmgr.bak  (daffcd580c2eb35cdfa41dc9fe08e401)

1 / 68      (Adware)
{0e908421-978e-4f01-bb7d-0e5e5b3fcd40}gw.sys (StdLib)  (ab9509eab54bb1721ad10b2e689b3320)

1 / 68      (Adware)
thirteendegreesuninstall.exe  (ba072db9da6c821c937467fca78946ca)

1 / 68      (Adware)
thirteendegrees.expext.exe  (19fcaf63aa1958855f1a6b1e098b8c5a)

1 / 68      (Adware)
thirteendegrees.purbrowse64.exe  (73869a8f3ac1bc356bc5cb296df6298b)

1 / 68      (Adware)
thirteendegrees.browseradapter64.exe  (206f48e3d453158e12fede1ecd377505)

1 / 68      (Adware)
{f6b23c67-8ae5-4397-bc1d-e8842b6f34bf}w.sys (StdLib)  (ec195c9eeada68c09c8029cc2ef148c0)

1 / 68      (Adware)
thirteendegrees.findlib.dll  (7eeec8f5e67eaaa77898b6ffa37217a9)

1 / 68      (Adware)
d3c1a623da64.dll  (269d591cdcdc41a1aa3465064e0653ec)

1 / 68      (Adware)
d3c1a623da.dll  (58539b35e749aa745b4d0cff52b03c9a)

1 / 68      (Adware)
d3c164.dll (by TODO: <Company name>)  (f7051dc2a82ed592a36379ca4bc5e097)

1 / 68      (Adware)
d3c1.dll (by TODO: <Company name>)  (276dc03536d1b10979c25e50f740f842)

1 / 68      (Adware)
217c9fd05264.dll  (d4e649e2fca1505e74e2d7f4b19821c2)

1 / 68      (Adware)
217c9fd052.dll  (7e21c0798b6fa16a1f49274bae9f7433)

1 / 68      (Adware)
217c64.dll (by TODO: <Company name>)  (7ba7a6e9a424f0f493ae641f86a06ae4)

1 / 68      (Adware)
217c.dll (by TODO: <Company name>)  (fb6f2dcd5543e1ae83ba5a47e32dc0e5)

1 / 68      (Adware)
thirteendegreesuninstall.exe  (90b80991ac345aa5151fe43badf63c70)

1 / 68      (Adware)
thirteendegreesun.exe  (acee5f5416ee36a370c1fac4b3d22fa8)

1 / 68      (Adware)
{ed37c808-8960-49ae-89d7-e7663d6f8309}gw64.sys (StdLib)  (dae23e555a84aa71c77322bf61697a2c)

1 / 68      (Adware)
{d3c1a623-dab6-4857-bbfa-4597ff935f9f}gw64.sys (StdLib)  (d13adf70233a4895604c5b07b933c0ab)

1 / 68      (Adware)
{b9b397c2-96d3-495c-868b-5dcbdedbd5e0}gw64.sys (StdLib)  (4d99dc3d4e969c51d0a4df8076cbed7c)

 
Latest 30 of 10,121 files

The following publishers (by Authenticode signature organization name) are related.

30 of 58 publishers

* Note, the details and description above are based on the code signing digital signature issued to thirteen degrees by VeriSign, Inc. on April 30, 2015 with the serial number '7ec505cb2a21f49edc7f06fd1e77efc8'.