updater.exe

The application updater.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “UpdaterSvcNetCrawl”. This file is typically installed with the program NetCrawl by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Version:
1.0.0.3

MD5:
cb914169c1863b9590436d2cc3c471c9

SHA-1:
d4f4adea82673b961f3e664da0918e8efb09b04e

SHA-256:
4522a8173daa7f027770385bd1d061883396285235798358e7622f222bd73597

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/23/2024 7:23:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11395861
865

Agnitum Outpost
Riskware.Agent
7.1.1

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14922

Bitdefender
Trojan.Generic.11395861
1.0.20.1325

Dr.Web
Trojan.BPlug.90
9.0.1.0182

Emsisoft Anti-Malware
Trojan.Generic.11395861
8.14.09.22.02

ESET NOD32
Win32/BrowseFox
8.10022

Fortinet FortiGate
Riskware/BrowseFox
7/1/2014

F-Secure
Trojan.Generic.11395861
11.2014-22-09_2

G Data
Trojan.Generic.11395861
14.9.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13198

McAfee
Artemis!B79C1B46C1C8
5600.6999

MicroWorld eScan
Trojan.Generic.11395861
15.0.0.795

NANO AntiVirus
Trojan.Win32.BPlug.dbonrn
0.28.0.60475

nProtect
Trojan.Generic.11395861
14.08.29.01

Panda Antivirus
Trj/CI.A
14.09.22.02

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.14

Rising Antivirus
PE:Trojan.Win32.Generic.170C5DF9!386686457
23.00.65.14920

Sophos
Generic PUA MG
4.98

Trend Micro House Call
TROJ_GEN.R002H09GR14
7.2.265

File size:
107 KB (109,568 bytes)

Product version:
1.0.0.3

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\netcrawl\updater.exe

File PE Metadata
Compilation timestamp:
6/18/2014 1:49:37 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:bePTx35AX//J2GYRzNaL4M80jmwGd4PccoAeEYHCEsWjcdh4KIpTJeyRH:KZ+2y8amZKWTDirhTIpTJeGH

Entry address:
0x836B

Entry point:
E8, 8D, 4B, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, 28, 69, 41, 00, E8, 8F, 00, 00, 00, FF, 35, FC, 96, 41, 00, FF, 15, 6C, 11, 41, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 01, 00, 00, 00, CC, 6A, 08, 68, 08, 69, 41, 00, E8, 57, 00, 00, 00, E8, 0C, 32, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 9F, 4C, 00, 00, CC, E8, E4, 31, 00, 00, 8B, 40, 7C, 85, C0...
 
[+]

Code size:
63.5 KB (65,024 bytes)

Service
Display name:
UpdaterSvcNetCrawl

Type:
Win32OwnProcess

Depends on:
RPCSS


The file updater.exe has been discovered within the following programs.

NetCrawl  by Yontoo Technology, Inc.
NetCrawl is an adware program from Yontoo that integrates into the user's web browsers (IE, Chrome, Firefox) and will perform a number of functions mostly designed to generate advertising supported or affiliate revenue.
netcrawl.info/support
81% remove it
 
Powered by Should I Remove It?

Remove updater.exe - Powered by Reason Core Security