6lyijjabnpqtugozbwficcuae2wu6lyijjabnpqtugozbwficcuae2wu_a9.exe

3790_pcm_istartsurf

Shulan Hou

The application 6lyijjabnpqtugozbwficcuae2wu6lyijjabnpqtugozbwficcuae2wu_a9.exe by Shulan Hou has been detected as adware by 11 anti-malware scanners.
Publisher:
AnyLink.com  (signed by Shulan Hou)

Product:
3790_pcm_istartsurf

Description:
AnyLink

Version:
6.6.86.1618

MD5:
fae378389b19073a719aecd2455fc9d8

SHA-1:
7910f8409ba2289d38111b06379ce9a54b8ff574

SHA-256:
ba46aab9efe7322a0251eb415051e7a7bd8b458aa4700108dd676db0cbb6bad3

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
11/23/2024 10:46:16 AM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Patched-JI
160518-2

AVG
Win32/Slugin.A
2015.0.4591

Dr.Web
Adware.Mutabaha.362, Win32.Wplugin.1
9.0.1.05190

Emsisoft Anti-Malware
Win32.SlugIn
11.5.0.6191

ESET NOD32
Win32/Agent.NAG virus
8.0.319.0

F-Prot
W32/Slugin.B
4.6.5.141

Kaspersky
Virus.Win32.Slugin
15.0.0.562

McAfee
Virus.W32/Wplugin
18.0.204.0

Microsoft Security Essentials
Threat.Undefined
1.223.1671.0

Norman
Win32.SlugIn.A
28.05.2016 15:32:18

Reason Heuristics
PUP.ELEX.ShulanHo (M)
16.6.17.9

File size:
850.1 KB (870,467 bytes)

Product version:
6.6.86.1618

Copyright:
Copyright (C) AnyLink.com 2008

Original file name:
AnyLink.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\{random}.tmp\o6lyijjabnpqtugozbwficcuae2wu6lyijjabnpqtugozbwficcuae2wu\6lyijjabnpqtugozbwficcuae2wu6lyijjabnpqtugozbwficcuae2wu_a9.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
12/24/2014 12:00:00 AM

Valid to:
1/6/2016 12:00:00 PM

Subject:
CN=Shulan Hou, O=Shulan Hou, L=Dingzhou, S=Hebei, C=CN

Issuer:
CN=DigiCert SHA2 Assured ID Code Signing CA, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
05E9B0F049A9F311A65A4CA8412DDCAA

File PE Metadata
Compilation timestamp:
5/15/2015 7:57:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:OfQyzebjNJr0pW9viajA6klgAoQjAjTVZ9/k0:OolbjNJr0pW9v4lgmoTVZ9/9

Entry address:
0x28428

Entry point:
60, E8, 00, 00, 00, 00, 5B, 81, EB, D0, 48, 00, 10, 83, EC, 74, 8B, EC, 8B, 83, AB, 4B, 00, 10, 89, 45, 00, 8B, 83, B3, 4B, 00, 10, 03, 45, 00, 89, 45, 2C, 8B, 83, B7, 4B, 00, 10, 03, 45, 00, 89, 45, 30, C7, 45, 14, 00, 00, 00, 00, C7, 45, 18, 00, 00, 00, 00, C7, 45, 1C, 00, 00, 00, 00, 8B, 45, 14, FF, 45, 14, 66, 33, C9, 8A, 8C, 03, FF, 4B, 00, 10, 84, C9, 74, 7A, 8B, 45, 1C, 66, 01, 4D, 1C, 03, C3, 05, 13, 4C, 00, 10, 50, 8B, 45, 2C, FF, 10, 85, C0, 0F, 84, 5E, 02, 00, 00, 89, 45, 10, 8B, 45, 1C, 03, C3...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
552 KB (565,248 bytes)