newjobupdate.exe

Shulan Hou

The application newjobupdate.exe by Shulan Hou has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service(NewjobU)”.
Publisher:
Shulan Hou  (signed and verified)

MD5:
014680c71e57d4ac9f44c1c4b62b6da6

SHA-1:
ceb8d62ae4c652f01e3357f4a0ecfe12b34d1dfd

SHA-256:
8d8eadfb1148edd793b6e688e6b700378518bbe200a288a62331f8d72aaa6a99

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
8/7/2025 4:32:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX (M)
17.2.11.23

File size:
14.5 MB (15,196,160 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\newjob\update\newjobupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
9/5/2016 3:00:00 AM

Valid to:
6/14/2017 2:59:59 AM

Subject:
CN=Shulan Hou, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
63970CDAB258E2D92B3B5296C2D97CB3

File PE Metadata
Compilation timestamp:
9/7/2016 10:34:48 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x4F7C8

Entry point:
E8, 68, 05, 00, 00, E9, 8E, FE, FF, FF, FF, 25, E0, 63, 47, 00, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 60, 49, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, F2, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 70, 60, 49, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45...
 
[+]

Entropy:
0.4704

Code size:
467 KB (478,208 bytes)

Service
Display name:
Update Service(NewjobU)

Service name:
NewjobU

Description:
Keeps your Newjob software up to date. If this service is disabled or stopped, your Newjob software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and fea

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove newjobupdate.exe - Powered by Reason Core Security