updater.exe

Zebar

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application updater.exe by Zebar has been detected as adware by 12 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “UpdaterSvcZebar”. This file is typically installed with the program Zebar by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Zebar  (signed and verified)

Version:
1.0.0.4

MD5:
734b0546ee0bcdba1e0bedcc505386b3

SHA-1:
004ebecabaabb1b78edd00d1d64dba39ac891ead

SHA-256:
089cdad1b3878ef3a3e39357787ab236a6c78937352cf384342a36b3c3a91f9a

Scanner detections:
12 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 6:01:33 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.SwiftBrowse.1
926

AVG
Zebrar
2015.0.3404

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14723

Bitdefender
Gen:Variant.Adware.SwiftBrowse.1
1.0.20.1020

Emsisoft Anti-Malware
Gen:Variant.Adware.SwiftBrowse
8.14.07.23.12

ESET NOD32
Win32/BrowseFox (variant)
8.10092

Fortinet FortiGate
Riskware/BrowseFox
7/23/2014

F-Secure
Gen:Variant.Adware.SwiftBrowse.1
11.2014-23-07_4

G Data
Gen:Variant.Adware.SwiftBrowse
14.7.24

McAfee
Artemis!734B0546EE0B
5600.7060

MicroWorld eScan
Gen:Variant.Adware.SwiftBrowse.1
15.0.0.612

Reason Heuristics
PUP.Zebar.H
14.7.23.12

File size:
132.8 KB (135,960 bytes)

Product version:
1.0.0.4

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\zebar\updater.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/9/2014 7:00:00 PM

Valid to:
3/10/2015 6:59:59 PM

Subject:
CN=Zebar, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Zebar, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
443A7E0E2025885A74F146162C4BEE38

File PE Metadata
Compilation timestamp:
7/9/2014 1:14:48 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:jAZDAYrRXnn5N6T7pp1IMTuTjw/lj2ttUBm1j9AGAfRcZ+IH1nT0sWjcdT5fIVTD:jAJVJ6eCBgWGAfE7V3T5IVTHxiqpZW3S

Entry address:
0x9CFB

Entry point:
E8, 01, 70, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, F8, B2, 41, 00, E8, 8F, 00, 00, 00, FF, 35, F4, E6, 41, 00, FF, 15, 88, 51, 41, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 01, 00, 00, 00, CC, 6A, 08, 68, D8, B2, 41, 00, E8, 57, 00, 00, 00, E8, 26, 3E, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 13, 71, 00, 00, CC, E8, FE, 3D, 00, 00, 8B, 40, 7C, 85, C0...
 
[+]

Code size:
79.5 KB (81,408 bytes)

Service
Display name:
UpdaterSvcZebar

Type:
Win32OwnProcess

Depends on:
RPCSS


The file updater.exe has been discovered within the following programs.

Zebar  by Yontoo Technology, Inc.
The Yontoo Zebar adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of search-related ads, banner and video ads, and text-links and some popup/pop-under advertisements.
metalzebar.com/support
84% remove it
 
Powered by Should I Remove It?

Remove updater.exe - Powered by Reason Core Security