utilnetcrawl.exe

NetCrawl

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilnetcrawl.exe by NetCrawl has been detected as adware by 8 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update NetCrawl”. This file is typically installed with the program NetCrawl by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
NetCrawl  (signed and verified)

Version:
1.0.5263.29514

MD5:
f7a543b4651a47873efd292850dde522

SHA-1:
a599fbd7aecae18f5102030f60d309bd208c65b4

SHA-256:
84dfdc254b5f9b22b832dec6b21aa14dd67fab10145a37dc09b2e00e49f1fbc0

Scanner detections:
8 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 2:56:47 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
NetCrawl
2015.0.3424

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.1473

ESET NOD32
Win32/BrowseFox.H potentially unwanted application
7.0.302.0

IKARUS anti.virus
AdWare.WebCake
t3scan.1.6.1.0

Malwarebytes
PUP.Optional.NetCrawl.A
v2014.07.03.05

Reason Heuristics
PUP.Service.NetCrawl.M
14.6.29.12

Trend Micro House Call
Suspicious_GEN.F47V0623
7.2.184

VIPRE Antivirus
Threat.4150696
29708

File size:
310.3 KB (317,728 bytes)

Product version:
1.0.5263.29514

Original file name:
NetCrawl.exe

File type:
Executable application (Win32 EXE)

Language:
Turkish (Turkey)

Common path:
C:\Program Files\netcrawl\bin\utilnetcrawl.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/29/2014 3:00:00 AM

Valid to:
4/30/2015 2:59:59 AM

Subject:
CN=NetCrawl, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=NetCrawl, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C05F8D25EB72CD5B6EB863AA0585F70

File PE Metadata
Compilation timestamp:
5/30/2014 8:24:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:cQBn8jM5lriESkmC7tLI6JZuWUx6V5dHubaJqddd:cQB+MLiEpJUfxG5FzoT

Entry address:
0x4D5A6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, D8, 02, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
301.5 KB (308,736 bytes)

Service
Display name:
Update NetCrawl

Type:
Win32OwnProcess


The file utilnetcrawl.exe has been discovered within the following programs.

NetCrawl  by Yontoo Technology, Inc.
NetCrawl is an adware program from Yontoo that integrates into the user's web browsers (IE, Chrome, Firefox) and will perform a number of functions mostly designed to generate advertising supported or affiliate revenue.
netcrawl.info/support
81% remove it
 
Powered by Should I Remove It?

Remove utilnetcrawl.exe - Powered by Reason Core Security