updatenetcrawl.exe

NetCrawl

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for NetCrawl will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatenetcrawl.exe by NetCrawl has been detected as adware by 5 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update NetCrawl”. This file is typically installed with the program NetCrawl by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
NetCrawl  (signed and verified)

Version:
1.0.5294.37082

MD5:
a55744a9b6eda223949fd2b2f8981385

SHA-1:
bfef4d539ee292a3a4ae67eacf8db762434ba685

SHA-256:
ac2498d9d36d67ae6d32b44c5d5dab86867c30d1cc7c7a3093a5554623cf5569

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
6/23/2024 6:15:59 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
NetCrawl
2015.0.3427

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1471

ESET NOD32
Win32/BrowseFox (variant)
8.10025

Malwarebytes
PUP.Optional.NetCrawl.A
v2014.07.01.04

Reason Heuristics
Adware.Yontoo.NetCrawl.O
14.7.1.4

File size:
311.3 KB (318,752 bytes)

Product version:
1.0.5294.37082

Original file name:
NetCrawl.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\netcrawl\updatenetcrawl.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/29/2014 7:00:00 AM

Valid to:
4/30/2015 6:59:59 AM

Subject:
CN=NetCrawl, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NetCrawl, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C05F8D25EB72CD5B6EB863AA0585F70

File PE Metadata
Compilation timestamp:
7/1/2014 4:36:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:BFkBn8cuzpg9Xm5kaCMpvWo+iw7UXruQaubZu:BFkBdu4XmiYw4XSDqu

Entry address:
0x4D8CA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
302.5 KB (309,760 bytes)

Service
Display name:
Update NetCrawl

Type:
Win32OwnProcess


The file updatenetcrawl.exe has been discovered within the following programs.

NetCrawl  by Yontoo Technology, Inc.
NetCrawl is an adware program from Yontoo that integrates into the user's web browsers (IE, Chrome, Firefox) and will perform a number of functions mostly designed to generate advertising supported or affiliate revenue.
netcrawl.info/support
81% remove it
 
Powered by Should I Remove It?

Remove updatenetcrawl.exe - Powered by Reason Core Security