maintainer.exe

ConstaSurf

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application maintainer.exe by ConstaSurf has been detected as adware by 30 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “MaintainerSvc3.04.9247444”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
ConstaSurf  (signed and verified)

Version:
1.0.5509.33369

MD5:
8b5e5440e0dae2fbf708bc5a9ded1ea2

SHA-1:
bed1b22d64077fabcefb638ddbc774565024f09c

SHA-256:
2b5c416336370fc2e6238af0d9777bcaa5068db4c7f9b1b5f0525b3f1fe42796

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 8:43:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.N
734

AhnLab V3 Security
Adware/Win32.SwiftBrowse
2015.02.01

Avira AntiVirus
Adware/BrowseFox.apf
7.11.206.68

avast!
Win32:Adware-BYZ [PUP]
2014.9-150201

AVG
Generic6
2016.0.3212

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1521

Bitdefender
Adware.SwiftBrowse.N
1.0.20.160

Clam AntiVirus
Win.Adware.Agent-22685
0.98/21511

Comodo Security
Application.Win32.BrowseFox.B
20920

Dr.Web
Trojan.BPlug.437
9.0.1.032

Emsisoft Anti-Malware
Adware.SwiftBrowse.N
8.15.02.01.03

ESET NOD32
Win32/BrowseFox.V potentially unwanted
9.11104

F-Prot
W32/A-de841313
v6.4.7.1.166

F-Secure
Adware.SwiftBrowse.N
11.2015-01-02_1

G Data
Adware.SwiftBrowse
15.2.25

IKARUS anti.virus
AdWare.SwiftBrowse
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.193.14824

Kaspersky
not-a-virus:AdWare.Win32.Yotoon
14.0.0.2554

Malwarebytes
PUP.Optional.SwiftBrowse
v2015.02.01.03

McAfee
BrowseFox-FTR
5600.6868

MicroWorld eScan
Adware.SwiftBrowse.N
16.0.0.96

NANO AntiVirus
Riskware.Win32.Kranet.dgiwfc
0.30.0.65070

nProtect
Trojan-Clicker/W32.Yotoon.123680
15.01.30.01

Quick Heal
AdWare.Yotoon.A5
2.15.14.00

Reason Heuristics
PUP.Service.Yontoo
15.2.1.3

Sophos
Browse Fox
4.98

SUPERAntiSpyware
Adware.SwiftBrowse
10081

Vba32 AntiVirus
AdWare.Yotoon
3.12.26.3

VIPRE Antivirus
Yontoo
37152

Zillya! Antivirus
Adware.Kranet.Win32.476
2.0.0.2050

File size:
120.8 KB (123,680 bytes)

Product version:
1.0.5509.33369

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\8a64b500-91d9-42f2-8d4d-776c5ec0ee9c\maintainer.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/18/2014 5:00:00 PM

Valid to:
3/19/2015 4:59:59 PM

Subject:
CN=ConstaSurf, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ConstaSurf, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
46A82C62F93896A2C29C94EC6C4D8A3D

File PE Metadata
Compilation timestamp:
1/31/2015 6:32:28 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:j3eRgxyOpGX5sfnC6P2dV59IikYYf9J892bbY+mebcQ/Wm1sWjcdjPQI0ypxCO87:TK35/9oxfTk+hvn6jPQI0ypxCOY3bZvB

Entry address:
0x8A72

Entry point:
E8, 95, 57, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 68, B2, 41, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 79, 45, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 7A, F3, FF, FF, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
6.1794

Code size:
68.5 KB (70,144 bytes)

Service
Display name:
MaintainerSvc3.04.9247444

Type:
Win32OwnProcess

Depends on:
RPCSS


Remove maintainer.exe - Powered by Reason Core Security