updateappenable.exe

AppEnable

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for AppEnable will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updateappenable.exe by AppEnable has been detected as adware by 8 anti-malware scanners. This file is typically installed with the program AppEnable by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
AppEnable  (signed and verified)

Version:
1.0.5425.13223

MD5:
4e34bb0b58d0d8f937b200fb13e6e97f

SHA-1:
08bb85464e3a73ba87f294c40c99ee56d0c431f0

SHA-256:
819ebea597fa471736434ade3b8c0da05bf1f43c6eb0ba0cb7892da4d5e4423b

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/26/2024 8:09:18 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3213

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.15131

ESET NOD32
MSIL/BrowseFox (variant)
9.10704

Malwarebytes
PUP.Optional.AppEnable.A
v2015.01.31.07

McAfee
Artemis!4E34BB0B58D0
5600.6869

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.Yontoo.AppEnable
15.1.31.8

VIPRE Antivirus
Adware.BrowseFox
34698

File size:
513.7 KB (526,064 bytes)

Product version:
1.0.5425.13223

Original file name:
AppEnable.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\appenable\updateappenable.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2014 1:00:00 AM

Valid to:
9/3/2015 12:59:59 AM

Subject:
CN=AppEnable, O=AppEnable, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6860DA46B7B1033AEAA52297BEEE857A

File PE Metadata
Compilation timestamp:
11/8/2014 4:20:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:NGo4VmS0Rd1/opSdvOsEcsHx2GCJPdYu8:NGo4kD2N0FGd

Entry address:
0x8023E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9294

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
505 KB (517,120 bytes)

The file updateappenable.exe has been discovered within the following programs.

AppEnable  by Yontoo Technology, Inc.
AppEnable is an adware program (supported by various types of advertising) that is usually bundled by third party installers and download managers.
appenable.info/support
80% remove it
 
Powered by Should I Remove It?

Remove updateappenable.exe - Powered by Reason Core Security