AdvanceMark

AdvanceMark

Known Malware

by Yontoo Technology, Inc.

What is AdvanceMark?

AdvanceMark is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 52.38% of installations running this operating system. AdvanceMark's installer is typically 2.00 MB in size and installs around 9 files. The most common release is 2014.02.26.045520 with 14.29% of all installations currently using this version.

AdvanceMark is most popular in Italy with 34.15% of installations residing in this country.

About AdvanceMark?

AdvanceMark is an ad-supported web browser extension that may be considered unwanted by some users. It has the capability to display popup and banner ads, as well as modify the user's web browser search and home page settings. This plugin is compatible with Internet Explorer (as a BHO), Chrome (as an extension), and Firefox (as an add-in). Additionally, the program has the potential to monitor user behavior, as outlined in the EULA. Users should carefully review the full End User License Agreement before installing the software.

Multiple virus scanners have detected malware in AdvanceMark.

updateAdvanceMark.exe (MD5: eb56c56ee38e81a6cf47f573ac422ece) has been flagged by 25 scanners:
Scanner Software Result
Agnitum Outpost Riskware.Agent!
AhnLab-V3 PUP/Win32.Downloader
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/MSIL.Kranet
AVG Generic.C7B
Avira ADWARE/BrowseFox.Gen7
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.BH
CAT-QuickHeal AdWare.MSIL.r3 (Not a Virus)
Comodo Security ApplicUnwnt
Dr.Web Trojan.BPlug.250
ESET-NOD32 a variant of Win32/BrowseFox.H
Fortinet FortiGate Adware/Kranet
IKARUS anti.virus PUA.BrowseFox
K7 AntiVirus Trojan ( 0049f7ad1 )
K7GW Trojan ( 020000001 )
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Kranet.heur
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.AdvanceMark.A
McAfee BrowseFox.c
McAfee-GW-Edition BehavesLike.Win32.AdwareMBrowse.fh
Qihoo-360 Win32/Virus.Adware.e4c
Sophos Generic PUA GP
Trend Micro TROJ_GEN.R0C1C0PJE14
TrendMicro-HouseCall TROJ_GEN.R0C1C0PJE14
VIPRE Antivirus Yontoo (fs)
AdvanceMarkBHO.dll (MD5: 172bf64c9057b62e2d7a75508bd3f56d) has been flagged by 32 scanners:
Scanner Software Result
Agnitum Outpost PUA.Agent
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
avast! Win32:PUP-gen [PUP]
AVG Agent.W
Baidu-International Adware.Win32.Agent.AWLP
CAT-QuickHeal AdWare.Agent.r5 (Not a Virus)
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.28
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
G Data Win32.Application.BrowseFox
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
Jiangmin Adware/Agent.jaw
K7 AntiVirus Unwanted-Program
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.AdvanceMark.A
McAfee Artemis!172BF64C9057
McAfee-GW-Edition Artemis!172BF64C9057
NANO AntiVirus Riskware.Win32.Agent.cqvnby
Sophos Generic PUA GI
SUPERAntiSpyware Adware.BrowseFox/Variant
TrendMicro-HouseCall TROJ_GEN.F47V0326
Vba32 AntiVirus AdWare.Agent
VIPRE Antivirus Yontoo (fs)
AhnLab-V3 PUP/Win32.Downloader
Avira ADWARE/BrowseFox.Gen7
AVware Yontoo (fs)
Qihoo-360 Win32/Virus.Adware.e4c
Trend Micro TROJ_GEN.R0C1C0PJE14

Software Behaviors

Services:
  • updateAdvanceMark.exe runs as a service named 'Update AdvanceMark' (Update AdvanceMark).

Software Details

URL:
https://advancemark.info/support
Support:
https://mailto:
Installation path:
C:\Program Files\AdvanceMark
Uninstaller:
C:\Program Files\AdvanceMark\AdvanceMarkuninstall.exe
Size:
2.00 MB
Language:
English

AdvanceMark Executable Details

Primary executable:
AdvanceMark.FirstRun.exe
Name:
AdvanceMark
Path:
C:\Program Files\AdvanceMark\AdvanceMark.FirstRun.exe
MD5:
SHA-1:
SHA-256:
Files installed by AdvanceMark
File Type Filename MD5
EXE
e92604e043f51c604b6d1ac3bcd3a202
EXE
eb56c56ee38e81a6cf47f573ac422ece
EXE
cfb923a1ab116d84e5757f50a562c1d8
DLL
172bf64c9057b62e2d7a75508bd3f56d
EXE
cc3e54d0e577b8c37aacf88478e82cbb
CRX
5225ac2289d78ebbfa1d3af2afe4e52e
EXE
fee2334b9e7c05a2fd7cee42e41cbfb1
DLL
a7dc4a11bbd192850cfc33fb43aad698
EXE
a879c23b3b84bcbf431f4d524d82d14c