updatepodoweb.exe

PodoWeb

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for PodoWeb will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatepodoweb.exe by PodoWeb has been detected as adware by 5 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update PodoWeb”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
PodoWeb  (signed and verified)

Version:
1.0.5408.15325

MD5:
09b581e7f709ad6e9a7faba2af80f8f8

SHA-1:
726402277737a91c0194c5a68346b7666b38c251

SHA-256:
633ced840a2bc05f293a4f765c13e9702eefc8e14fba9a24e87cb0ec133135ff

Scanner detections:
5 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/19/2024 9:03:58 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3313

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.141022

ESET NOD32
MSIL/BrowseFox (variant)
8.10604

Malwarebytes
PUP.Optional.PodoWeb.A
v2014.10.22.05

Reason Heuristics
Adware.Yontoo.Service.N
14.10.22.17

File size:
511.2 KB (523,504 bytes)

Product version:
1.0.5408.15325

Original file name:
PodoWeb.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\podoweb\updatepodoweb.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/7/2014 1:00:00 AM

Valid to:
10/8/2015 12:59:59 AM

Subject:
CN=PodoWeb, O=PodoWeb, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
00D53DF9C14BCAA20E79F402AA9DD4F5

File PE Metadata
Compilation timestamp:
10/22/2014 5:31:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:6MFEem/T44qIFe2zbMw/IYTpYOQ3MhEBwTE:6rem/T7N/I18GKT

Entry address:
0x7F8A6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 5A, 00, 00, 00, E8, F8, 07, 00, E8, DA, 07, 00, 52, 53, 44, 53, 60, 39, 88, F4, 95, DE, 33, 44, 9B, 5C, E2, 01, 73, 07, B1, 44, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 65, 31, 7A, 6C, 61, 70, 79, 64, 2E, 6A, 74, 69, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
502.5 KB (514,560 bytes)

Service
Display name:
Update PodoWeb

Type:
Win32OwnProcess


Remove updatepodoweb.exe - Powered by Reason Core Security