krabweb.dll

Krab Web

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module krabweb.dll by Krab Web has been detected as adware by 10 anti-malware scanners. This file is typically installed with the program Krab Web by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Krab Web  (signed and verified)

Product:
Krab Web

Version:
1.0.0.3

MD5:
1dceb556f9e6fc0a59a06988f0d5186d

SHA-1:
64453ff59ebe39ce41ba0e12a1b6f5810a4bb412

SHA-256:
539bb4711dafadd76eb5f32edece08424c945ee4b9ff92a5f7d9bba8f7213b40

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
1/14/2025 9:41:50 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.182.144

AVG
BrowseFox.F
2015.0.3303

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14111

Comodo Security
Application.Win32.BrowseFox.JM
19955

Dr.Web
Trojan.BPlug.144
9.0.1.0305

ESET NOD32
Win32/BrowseFox (variant)
8.10651

Malwarebytes
PUP.Optional.KrabWeb.A
v2014.11.01.03

McAfee
BrowseFox-FRR
5600.6959

NANO AntiVirus
Trojan.Win32.BPlug.dfogbn
0.28.6.62995

Reason Heuristics
PUP.KrabWeb.H
14.11.1.15

File size:
244.2 KB (250,096 bytes)

Product version:
1.0.0.3

Copyright:
(c) Krab Web. All rights reserved.

Original file name:
Krab WebIEClient.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\z5k2metf\krabweb.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/6/2014 8:00:00 PM

Valid to:
10/7/2015 7:59:59 PM

Subject:
CN=Krab Web, O=Krab Web, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7267FFF9DE9B65FB24D2CA9CB6A3E8F9

File PE Metadata
Compilation timestamp:
10/31/2014 3:00:16 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:3RxoOBfVfdiKQkpiUFjIlige9eAxjN+/IaINCBLdfaU:35BfVfRQSiQeGYIcBdfaU

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 70, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 04, 78, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, FC, A4, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3604

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file krabweb.dll has been discovered within the following programs.

Krab Web  by Yontoo Technology, Inc.
Krab Web is an advertising supported browser extension also known as adware and is designed to deliver ads to the user's Internet browser as banners, context text-links and transitionals ads. The injected ads are not affiliated with the underlying website on which they appear.
krabweb.net/support
81% remove it
 
Powered by Should I Remove It?

Remove krabweb.dll - Powered by Reason Core Security