updateappenable.exe

AppEnable

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for AppEnable will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updateappenable.exe by AppEnable has been detected as adware by 9 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update AppEnable”. Additionally, the file is typically installed by a number of programs including AppEnable by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
AppEnable  (signed and verified)

Version:
1.0.5439.24071

MD5:
2795bce144cfe6c728d9b96ecaaaed47

SHA-1:
75da7afd9420f0cb3052a4fdeab084bb31428d12

SHA-256:
523fdfa4d2e145fe5595f8c45a376bd1588c382019edf4943ef5f3cc2a42c31f

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
5/10/2024 10:07:57 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
Adware/BrowseFox.aok
7.11.188.58

AVG
Generic
2015.0.3282

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.141122

ESET NOD32
MSIL/BrowseFox (variant)
8.10766

K7 AntiVirus
Adware
13.185.14098

Malwarebytes
PUP.Optional.AppEnable.A
v2014.11.22.09

Qihoo 360 Security
HEUR/QVM03.0.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.Yontoo.Service.P
14.11.22.21

Sophos
Browse Fox
4.98

File size:
413.2 KB (423,152 bytes)

Product version:
1.0.5439.24071

Original file name:
AppEnable2014112221.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\appenable\updateappenable.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
9/2/2014 8:00:00 AM

Valid to:
9/3/2015 7:59:59 AM

Subject:
CN=AppEnable, O=AppEnable, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6860DA46B7B1033AEAA52297BEEE857A

File PE Metadata
Compilation timestamp:
11/23/2014 5:22:22 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:RGjhq5ZiSnm0I5c2Gou6YH+lNaruJ39XdJMYWtECCKTK+SZhQ6f+Rf9JArGpdHEE:Yjhqup8ouIa63R7hyECvTK+MhQbqaT

Entry address:
0x670FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8928

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
404.5 KB (414,208 bytes)

Service
Display name:
Update AppEnable

Type:
Win32OwnProcess


The file updateappenable.exe has been discovered within the following programs.

AppEnable  by Yontoo Technology, Inc.
AppEnable is an adware program (supported by various types of advertising) that is usually bundled by third party installers and download managers.
appenable.info/support
80% remove it
Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
 
Powered by Should I Remove It?

Remove updateappenable.exe - Powered by Reason Core Security