updater.exe

The application updater.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “UpdaterSvcwebget”. This file is typically installed with the program webget by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Version:
1.0.0.3

MD5:
259cf086762693f42812dec7749ee3e7

SHA-1:
cd0644ff57c7f68f97f38a7b0e51172f1902eaf6

SHA-256:
a746a7d5a2565608fd366238ac33cb1ea164af5984c08ac96160051f8c106aff

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/18/2024 11:22:56 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11395861
865

Agnitum Outpost
Riskware.Agent
7.1.1

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14922

Bitdefender
Trojan.Generic.11395861
1.0.20.1325

Dr.Web
Trojan.BPlug.90
9.0.1.0265

Emsisoft Anti-Malware
Trojan.Generic.11395861
8.14.09.22.02

ESET NOD32
Win32/BrowseFox
8.10337

Fortinet FortiGate
Riskware/BrowseFox
9/22/2014

F-Secure
Trojan.Generic.11395861
11.2014-22-09_2

G Data
Trojan.Generic.11395861
14.9.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13198

McAfee
Artemis!B79C1B46C1C8
5600.6999

MicroWorld eScan
Trojan.Generic.11395861
15.0.0.795

NANO AntiVirus
Trojan.Win32.BPlug.dbonrn
0.28.2.61861

nProtect
Trojan.Generic.11395861
14.08.29.01

Panda Antivirus
Trj/CI.A
14.09.22.02

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.14

Rising Antivirus
PE:Trojan.Win32.Generic.170C5DF9!386686457
23.00.65.14920

Sophos
Generic PUA MG
4.98

Trend Micro House Call
TROJ_GEN.R002H09GR14
7.2.265

File size:
107 KB (109,568 bytes)

Product version:
1.0.0.3

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\webget\updater.exe

File PE Metadata
Compilation timestamp:
6/2/2014 7:57:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:WePTx35AX//J2GYRzNaL4M80jmwGd4sccoAeEYHCEsWjcdX4KIpTJey1H:zZ+2y8amZdWTDirXTIpTJeqH

Entry address:
0x836B

Entry point:
E8, 8D, 4B, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, 28, 69, 41, 00, E8, 8F, 00, 00, 00, FF, 35, FC, 96, 41, 00, FF, 15, 6C, 11, 41, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 01, 00, 00, 00, CC, 6A, 08, 68, 08, 69, 41, 00, E8, 57, 00, 00, 00, E8, 0C, 32, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 9F, 4C, 00, 00, CC, E8, E4, 31, 00, 00, 8B, 40, 7C, 85, C0...
 
[+]

Code size:
63.5 KB (65,024 bytes)

Service
Display name:
UpdaterSvcwebget

Type:
Win32OwnProcess

Depends on:
RPCSS


The file updater.exe has been discovered within the following programs.

webget  by Yontoo Technology, Inc.
The webget adware injects advertising in the user's Internet browser by running as an extension and/or add-on. Ads are delivered in the form of banners and text-links (roll-overs) as well as some popup ads.
webwebget.com/support
84% remove it
 
Powered by Should I Remove It?

Remove updater.exe - Powered by Reason Core Security