newjobupdate.exe

Shulan Hou

The application newjobupdate.exe by Shulan Hou has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service(NewjobU)”.
Publisher:
Shulan Hou  (signed and verified)

MD5:
659934e2c41053de5b3e340a6a7f667d

SHA-1:
30986d9bd0376d8c4915e870b94e939f0920a23f

SHA-256:
3e9f683a362d3a658c8c8a71fc4d38eacac1b0b1603b99e60875ff9fc9f80b1e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/7/2025 10:31:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX.Service
17.2.4.17

File size:
13.4 MB (14,077,952 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\newjob\update\newjobupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/5/2016 3:00:00 AM

Valid to:
6/14/2017 2:59:59 AM

Subject:
CN=Shulan Hou, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
63970CDAB258E2D92B3B5296C2D97CB3

File PE Metadata
Compilation timestamp:
9/7/2016 10:34:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x4F7C8

Entry point:
E8, 68, 05, 00, 00, E9, 8E, FE, FF, FF, FF, 25, E0, 63, 47, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 60, 49, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 60, 49, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45...
 
[+]

Entropy:
0.5035

Code size:
467 KB (478,208 bytes)

Service
Display name:
Update Service(NewjobU)

Service name:
NewjobU

Description:
Keeps your Newjob software up to date. If this service is disabled or stopped, your Newjob software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and fea

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove newjobupdate.exe - Powered by Reason Core Security