updatebrowsefox.exe

Browse Fox

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for Browse Fox will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatebrowsefox.exe by Browse Fox has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update BrowseFox”. This file is typically installed with the program BrowseFox 3.0.0 by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Browse Fox  (signed and verified)

Version:
1.0.5164.35158

MD5:
b592a6b92a63ec177a1a1463c37e1820

SHA-1:
0c7b3652b9475a41c00421250e70a78ad159172e

SHA-256:
4fb9c7383ebd549fa6b8fc5af45a9b9e812fb3c9e6663ec287d27c588b642d01

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/25/2024 7:52:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo.BrowseFox (M)
16.1.29.13

File size:
108.8 KB (111,392 bytes)

Product version:
1.0.5164.35158

Original file name:
BrowseFox.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\browsefox\updatebrowsefox.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/30/2013 2:00:00 AM

Valid to:
7/31/2014 1:59:59 AM

Subject:
CN=Browse Fox, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Browse Fox, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3DA9F504A9E9628C2224F40C9EA90C86

File PE Metadata
Compilation timestamp:
2/20/2014 8:32:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:MWRTv1OGwqM/nc3S1yeVIIn0azc9ZBberL8nwG:MWRT9OGwqMECMeVNnpcdbeP2

Entry address:
0x1AE9A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
100 KB (102,400 bytes)

Service
Display name:
Update BrowseFox

Type:
Win32OwnProcess


The file updatebrowsefox.exe has been discovered within the following program.

BrowseFox 3.0.0  by Yontoo Technology, Inc.
This is a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search.
browsefox.com/support
78% remove it
 
Powered by Should I Remove It?

Remove updatebrowsefox.exe - Powered by Reason Core Security