airglobebho.dll

Air Globe

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module airglobebho.dll by Air Globe has been detected as adware by 36 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Air Globe 1.0.0.7’. This file is typically installed with the program Air Globe by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Air Globe  (signed and verified)

Product:
Air Globe

Version:
1.0.0.7

MD5:
3f9d7a7b1a3847f4abf1f67be34dc614

SHA-1:
29e02df1a2da1bcec59e0e8a85ebaa4677c36240

SHA-256:
684f12da84bfd4fc289057e4d4bfb000c372c131532dfb6907145f650c41dab8

Scanner detections:
36 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
12/26/2024 3:09:46 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.DO
393

Agnitum Outpost
Riskware.Agent
7.1.1

AhnLab V3 Security
PUP/Win32.BrowseFox
2015.07.07

Avira AntiVirus
ADWARE/BrowseFox.Gen2
8.3.1.6

AVG
AdPlugin
2017.0.2871

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1618

Bitdefender
Adware.BrowseFox.DO
1.0.20.40

Bkav FE
W32.HfsAdware
1.3.0.6979

Clam AntiVirus
Win.Adware.Agent-43030
0.98/21511

Comodo Security
ApplicUnwnt
22142

Dr.Web
Trojan.Yontoo.1734
9.0.1.08

Emsisoft Anti-Malware
Adware.BrowseFox.DO
8.16.01.08.08

ESET NOD32
Win32/BrowseFox.AE potentially unwanted (variant)
10.11897

Fortinet FortiGate
Riskware/BrowseFox
1/8/2016

F-Prot
W32/S-f64f6ec1
v6.4.7.1.166

F-Secure
Adware.BrowseFox.DO
11.2016-08-01_6

G Data
Adware.BrowseFox.DO
16.1.25

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.9.5.0

K7 AntiVirus
Trojan
13.205.16471

Malwarebytes
PUP.Optional.Airglobe
v2016.01.08.08

McAfee
Artemis!16B0E18D1437
5600.6527

MicroWorld eScan
Adware.BrowseFox.DO
17.0.0.24

NANO AntiVirus
Trojan.Win32.Yontoo.dnkubo
0.30.24.2320

nProtect
Adware.BrowseFox.DO
15.07.06.01

Panda Antivirus
PUP/AirGlobe
16.01.08.08

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
PUP.Yontoo.AirGlobe (M)
16.1.8.8

Rising Antivirus
PE:Adware.BrowseFox!6.1D8B
23.00.65.16106

Sophos
Generic PUA ME
4.98

SUPERAntiSpyware
Adware.Kranet/Variant
9398

Trend Micro House Call
TROJ_GEN.R0C1C0EDP15
7.2.8

Trend Micro
TROJ_GEN.R02SC0ODO15
10.465.08

Vba32 AntiVirus
AdWare.MSIL.Agent
3.12.26.4

VIPRE Antivirus
Yontoo
41768

ViRobot
Trojan.Win32.S.Agent.269040.E[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.PePatch.Win32.71219
2.0.0.2271

File size:
262.7 KB (269,040 bytes)

Product version:
1.0.0.7

Copyright:
(c) Air Globe. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\air globe\airglobebho.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/11/2015 7:00:00 AM

Valid to:
1/12/2016 6:59:59 AM

Subject:
CN=Air Globe, O=Air Globe, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0C68EFA725DB8110CE807489DAC03553

File PE Metadata
Compilation timestamp:
4/24/2015 6:03:22 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:u2CYUE9J7yX8LVxQbqHVOhB+PVG63Qv+hp2mZKTFRtk2cgP:u2CYUi+sLVW4VOy+6AmZqu9w

Entry address:
0xF515

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, EA, 7E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, B8, 21, 03, 10, E8, 4C, 02, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 0C, 77, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, C4, 93, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.0714

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
Air Globe 1.0.0.7

CLSID:
{4c54ce3d-6b7d-4f21-9e69-200632a98540}


The file airglobebho.dll has been discovered within the following programs.

Air Globe  by Yontoo Technology, Inc.
From Yontoo's License Agreement: "The Software is supported by several forms of advertising, which will be displayed as you use your browsers, including, without limitation, banner and video ads, in-text ads and links, web browsing-related ads, interstitial, transitional, search, and full page ads.
airglobeapp.com/support
80% remove it
 
Powered by Should I Remove It?

The file airglobebho.dll has been seen being distributed by the following 2 URLs.

Remove airglobebho.dll - Powered by Reason Core Security