holdpage.dll

middle pages

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module holdpage.dll by middle pages has been detected as adware by 18 anti-malware scanners. This file is typically installed with the program Hold Page by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. The file has been seen being downloaded from install-cdn.holdingmypage.com.
Publisher:
Hold Page  (signed by middle pages)

Product:
Hold Page

Version:
1.0.0.5

MD5:
e6c8e59202148337161c0c68bc6a9cd0

SHA-1:
675d8747d0917cffe8f0ff8afc723fe615fd089b

SHA-256:
5d7fd528da8f0d3a4e6212f445e4d996e074239f5ad227aec034967d08fb181a

Scanner detections:
18 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
12/26/2024 5:45:40 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.BrowseFox.AL
783

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.195.56

AVG
BrowseFox.F
2015.0.3261

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.141213

Bitdefender
Adware.BrowseFox.AL
1.0.20.1735

Comodo Security
Application.Win32.BrowseFox.JM
20357

Dr.Web
Trojan.BPlug.215
9.0.1.0347

Emsisoft Anti-Malware
Adware.BrowseFox.AL
8.14.12.13.10

ESET NOD32
Win32/BrowseFox (variant)
8.10872

F-Secure
Adware.BrowseFox.AL
11.2014-13-12_7

G Data
Adware.BrowseFox.AL
14.12.24

K7 AntiVirus
Trojan
13.187.14319

Malwarebytes
PUP.Optional.HoldPage.A
v2014.12.13.10

MicroWorld eScan
Adware.BrowseFox.AL
15.0.0.1041

NANO AntiVirus
Trojan.Win32.BPlug.dfogbn
0.28.6.63850

Reason Heuristics
PUP.middlepages
15.1.12.11

Vba32 AntiVirus
AdWare.SwiftBrowse
3.12.26.3

VIPRE Antivirus
Yontoo
35690

File size:
244.2 KB (250,096 bytes)

Product version:
1.0.0.5

Copyright:
(c) Hold Page. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\tg7rs92s\holdpage.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/6/2014 7:00:00 PM

Valid to:
10/2/2015 6:59:59 PM

Subject:
CN=middle pages, O=middle pages, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
01FD540333A96486522A2EDFD3C2E0B3

File PE Metadata
Compilation timestamp:
12/12/2014 11:24:14 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:XUhotD3yNoza354yklBTA7KuTTci+/IaIH1M1Ezl:X1D3yNP3Wy94IVUEzl

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 80, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 04, 78, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 0C, A5, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3613

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file holdpage.dll has been discovered within the following programs.

Hold Page  by Yontoo Technology, Inc.
Hold Page is an adware program that installs as a web browser plugin to inject and display advertisements.
holdingmypage.com/support
87% remove it
 
Powered by Should I Remove It?

The file holdpage.dll has been seen being distributed by the following URL.

Remove holdpage.dll - Powered by Reason Core Security