tiblfyubuei.dll

Green Fire Software

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The module tiblfyubuei.dll by Green Fire Software has been detected as adware by 3 anti-malware scanners.
Publisher:
Green Fire Software  (signed and verified)

MD5:
92b5f18580da0ad71939b7526d068845

SHA-1:
64c635c0af9a03df7068a9e4fbe1a73b0476fa53

SHA-256:
0b6741d1e01f8cd7d155e2e323dbebe47133ffc9ce95325b325f54b156abaeb0

Scanner detections:
3 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
10/18/2024 4:18:33 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
CreativeIsland
2015.0.3351

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.14.14

VIPRE Antivirus
Threat.4784449
29708

File size:
1.3 MB (1,382,256 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\ProgramData\qugpemyv\dat\tiblfyubuei.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/19/2013 8:00:00 PM

Valid to:
9/20/2014 7:59:59 PM

Subject:
CN=Green Fire Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Green Fire Software, L=La Jolla, S=California, C=US

Serial number:
38E34FCC0FDD5E91FD5048A198AAABF1

File PE Metadata
OS bitness:
Win64

CTPH (ssdeep):
24576:j9jJwPnuxN6Y7ZkQpnIy9efeTOD+1OEr/+Rx5TTNRtiJ:j9jJwPu+LUIycfLEKR/TN

Entry point:
48, 89, 5C, 24, 08, 48, 89, 74, 24, 10, 57, 48, 83, EC, 20, 49, 8B, F8, 8B, DA, 48, 8B, F1, 83, FA, 01, 75, 05, E8, 73, C5, 00, 00, 4C, 8B, C7, 8B, D3, 48, 8B, CE, 48, 8B, 5C, 24, 30, 48, 8B, 74, 24, 38, 48, 83, C4, 20, 5F, E9, A7, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83, F8, 40, 72, 1E, 48, F7, D9, 83, E1, 07, 74, 06, 4C, 2B, C1, 48, 89, 10, 48, 03...
 
[+]

Remove tiblfyubuei.dll - Powered by Reason Core Security