yontoo-c4.exe

DropDownDeals

Web Deals Interactive LLC

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser as well as modify the computer’s system settings that control applications to run on startup. Part of the Injekt brand of unwanted programs. The application yontoo-c4.exe by Web Deals Interactive has been detected as adware by 9 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. It is also typically executed from the user's temporary directory.
Publisher:
Web Deals Interactive LLC  (signed and verified)

Product:
DropDownDeals

Description:
Installer

Version:
2012.12.12.1306

MD5:
62520fed3ac0663f82061a8fb21e1f67

SHA-1:
63d8a233223061d42538ad5f8a1552a86c0420ca

SHA-256:
b6f74d1c39c8c0d29a29a2e5811cd06e20d739230e80fda2707afde65c8dd8e4

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
5/9/2024 1:15:50 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Generic
7.1.1

Baidu Antivirus
AdWare.Win32.Yontoo
4.0.3.131223

Comodo Security
UnclassifiedMalware
17223

Dr.Web
Adware.Plugin.8
9.0.1.0357

ESET NOD32
Win32/Adware.Yontoo (variant)
7.9012

Reason Heuristics
PUP.Installer.WebDealsInteractive.J
14.3.3.12

Rising Antivirus
Trojan.Win32.Generic.13E38AD4
23.00.65.131221

VIPRE Antivirus
Yontoo
23090

XVirus List
Win.Detected
2.3.31

File size:
1.3 MB (1,384,752 bytes)

Product version:
1.11.00

Copyright:
Copyright (c) 2012 Web Deals Interactive LLC. All rights reserv

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\yontoo-c4.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/15/2012 9:41:08 PM

Valid to:
5/15/2013 6:52:46 PM

Subject:
CN=Web Deals Interactive LLC, O=Web Deals Interactive LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
2B7631E3D31FB1

File PE Metadata
Compilation timestamp:
3/11/2011 3:55:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:VbfU+WkgP0GKHuKskjzGbAvClAELsY33bvTe1kpLZ7s8i4dA4Fmh3Uo0d5mSd:6zkg8zHuDoLCGELX7MkpLhsAd/FmpUp7

Entry address:
0x15B4

Entry point:
55, 8B, EC, 81, EC, CC, 05, 00, 00, 53, 56, 33, DB, 57, C6, 85, 34, FA, FF, FF, 00, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, 3C, FE, FF, FF, 50, C7, 85, 3C, FE, FF, FF, 94, 00, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, A8, 32, 40, 00, E8, 36, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, 20, 02, 00, 00, 8B, 35, 68, 30, 40, 00, 68, 94, 32, 40, 00, 68, 84, 32, 40, 00, FF, D6, 50, FF, 15, 64, 30, 40...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

Remove yontoo-c4.exe - Powered by Reason Core Security