utilsquirrelweb.exe

squirrelweb

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilsquirrelweb.exe by squirrelweb has been detected as adware by 6 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update SquirrelWeb”. This file is typically installed with the program SquirrelWeb by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
squirrelweb  (signed and verified)

Version:
1.0.5310.35448

MD5:
ee68577a1f02be6201e6dfe6778b6458

SHA-1:
9bc7acba0516d091a59ae283ec6c3d3f04b65dbf

SHA-256:
8cb049a15a81423f197dd1d2371d00afed133e66a436eefb6bd47d646767deb7

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 10:11:28 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Squiweb
2015.0.3405

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14723

ESET NOD32
Win32/BrowseFox.H potentially unwanted application
7.0.302.0

Malwarebytes
PUP.Optional.SquirrelWeb.A
v2014.07.23.09

Reason Heuristics
PUP.Service.squirrelweb.P
14.8.8.0

VIPRE Antivirus
Threat.4741131
31208

File size:
314.3 KB (321,824 bytes)

Product version:
1.0.5310.35448

Original file name:
SquirrelWeb.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\Program Files\squirrelweb\bin\utilsquirrelweb.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
10/7/2013 3:00:00 AM

Valid to:
10/8/2014 2:59:59 AM

Subject:
CN=squirrelweb, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=squirrelweb, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7244DFB846B028B3B64BA8B4A757EAA4

File PE Metadata
Compilation timestamp:
7/16/2014 11:41:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:u8zBn89rIlbMEwefk73nXNu89/ysqs7eaH4vlziXpb2V14n:u8zB4rIwecprR4SU3Q

Entry address:
0x4E5A2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, E0, 02, 00, 80, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
305.5 KB (312,832 bytes)

Service
Display name:
Update SquirrelWeb

Type:
Win32OwnProcess


The file utilsquirrelweb.exe has been discovered within the following program.

SquirrelWeb  by Yontoo Technology, Inc.
This is an unwanted web browser extension that delivers search hijacking as well as contextual advertising within a user's web browser. The program does this by modifying the user's home and search pages in order to monetize search activities.
squirrelweb.org/support
83% remove it
 
Powered by Should I Remove It?

Remove utilsquirrelweb.exe - Powered by Reason Core Security