updatebrowsefox.exe

Browse Fox

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for Browse Fox will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatebrowsefox.exe by Browse Fox has been detected as adware by 2 anti-malware scanners. This file is typically installed with the program BrowseFox 3.0.0 by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Browse Fox  (signed and verified)

Version:
1.0.5217.22427

MD5:
c67bfc00d8023eb3ae34f7a7e420765b

SHA-1:
449c850d132caff1d5922488f02b7654493f1c40

SHA-256:
ea10bd1f0760a628aec7216a68c66031a165f240d87c573e94011af979f9f775

Scanner detections:
2 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/25/2024 6:17:01 PM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.BrowseFox
188838

Reason Heuristics
PUP.Yontoo.BrowseFox (M)
16.2.3.16

File size:
342.3 KB (350,496 bytes)

Product version:
1.0.5217.22427

Original file name:
BrowseFox.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\browsefox\updatebrowsefox.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/29/2013 9:00:00 PM

Valid to:
7/30/2014 8:59:59 PM

Subject:
CN=Browse Fox, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Browse Fox, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3DA9F504A9E9628C2224F40C9EA90C86

File PE Metadata
Compilation timestamp:
4/14/2014 10:27:49 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:rE5C4vCX0YKVK41NWv2eVzN+OivIsTV3KmU4fmaH+Pu6JByRITxYcyb1cQ:rE5NeMfr+Pu6JByLvcQ

Entry address:
0x5555A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
333.5 KB (341,504 bytes)

The file updatebrowsefox.exe has been discovered within the following program.

BrowseFox 3.0.0  by Yontoo Technology, Inc.
This is a web browser extension and Browser helper Object (for Internet Explorer) that delivers contextual based advertising to the web browser. In addition it will modify the user's browser home and search pages as well as 'New Tab' pages to push advertising and search.
browsefox.com/support
78% remove it
 
Powered by Should I Remove It?

Remove updatebrowsefox.exe - Powered by Reason Core Security