updatepodoweb.exe

PodoWeb

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for PodoWeb will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatepodoweb.exe by PodoWeb has been detected as adware by 5 anti-malware scanners. This file is typically installed with the program PodoWeb by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
PodoWeb  (signed and verified)

Version:
1.0.5407.5476

MD5:
08f01c0366d0346fea039205b93200ec

SHA-1:
16da0bb06ce508d60a145711dd1960d97dae90c2

SHA-256:
7ee4a4650b6bf0cc18756544efe08adaa31f3942bdce211dd5e82e50ab6c59be

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/25/2024 2:50:42 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3313

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.141022

ESET NOD32
MSIL/BrowseFox (variant)
8.10604

Malwarebytes
PUP.Optional.PodoWeb.A
v2014.10.22.02

Reason Heuristics
Adware.Yontoo.PodoWeb.N
14.10.22.14

File size:
511.7 KB (524,016 bytes)

Product version:
1.0.5407.5476

Original file name:
PodoWeb.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\podoweb\updatepodoweb.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/7/2014 3:30:00 AM

Valid to:
10/8/2015 3:29:59 AM

Subject:
CN=PodoWeb, O=PodoWeb, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00D53DF9C14BCAA20E79F402AA9DD4F5

File PE Metadata
Compilation timestamp:
10/21/2014 2:32:38 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:DHHi93oGYdy4Rn5iv+1ZCNxpfqwD7ymdP6+zscb6rne:Dnilo3sVxpfpg

Entry address:
0x7F9F2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 5A, 00, 00, 00, 34, FA, 07, 00, 34, DC, 07, 00, 52, 53, 44, 53, 42, 02, F4, E2, EC, 7A, DC, 4C, B4, 2A, C0, D1, BE, 5C, A8, D7, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 63, 6C, 62, 6F, 63, 69, 32, 75, 2E, 61, 35, 74, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Entropy:
5.9193

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
503 KB (515,072 bytes)

The file updatepodoweb.exe has been discovered within the following program.

PodoWeb  by Yontoo Technology, Inc.
PodoWeb is an adware program that runs within the user's web browser and will modify various browser settings such as changing the search provider.
podoweb.net/support
82% remove it
 
Powered by Should I Remove It?

Remove updatepodoweb.exe - Powered by Reason Core Security