AdvanceElite.GCUpdate.dll

TasticSurf

This is the Google Chrome extension manager/updater for the Yontoo TasticSurf branded web browser plugin which injects banners, text-link and popup ads in the Chorme browser. The module AdvanceElite.GCUpdate.dll by TasticSurf has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
TasticSurf  (signed and verified)

Version:
1.0.5415.36864

MD5:
77614ca70a1ceccba2cd442d854334f3

SHA-1:
15479fd3e4655c35b15cf2010aaf4575c16c3f59

SHA-256:
e412c3c3e0bcb9ce4b98bc9b1f47d871f20f119af3a4621f7f020297f890e09f

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo distributed ad-supported web browser extension for Chrome.

Analysis date:
12/24/2024 12:06:03 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
16.12.6.6

File size:
1.6 MB (1,648,416 bytes)

Product version:
1.0.5415.36864

Original file name:
AdvanceElite.GCUpdate.dll

File type:
Dynamic link library (Win32 DLL)

Language:
Language Neutral

Common path:
C:\Program Files\advanceelite\bin\plugins\advanceelite.gcupdate.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/26/2013 10:00:00 PM

Valid to:
11/27/2014 9:59:59 PM

Subject:
CN=TasticSurf, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=TasticSurf, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7A9A017A31DB5E88B561FEDAF60E6163

File PE Metadata
Compilation timestamp:
10/30/2014 2:28:54 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
24576:UYXXNRId5XBJ6x+7xELm9dDml/6Ei4MAaZgq/ilNYdB+vSZ9Spb6Kbq+d+7eOqvp:5FPaZgq/isuIEcqv/j4sjHf

Entry address:
0x192446

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 71, 00, 00, 00, 88, 24, 19, 00, 88, 06, 19, 00, 52, 53, 44, 53, FA, 45, F8, 0A, 4D, 55, E7, 46, 87, 5F, B2, B4, F4, 8D, 5A, 54, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 79, 6A, 63, 79, 35, 75, 74, 64, 2E, 62, 75, 71, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
1.6 MB (1,639,936 bytes)

Remove AdvanceElite.GCUpdate.dll - Powered by Reason Core Security