krabwebuninstall.exe

Krab Web

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application krabwebuninstall.exe by Krab Web has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is the uninstaller utility registered in the Windows Control Panel for the program Krab Web by Krab Web. Additionally, the file is typically installed by a number of programs including Buzzdock by Alactro LLC and Krab Web by Yontoo Technology, Inc., both potentially unwanted software.
Publisher:
Krab Web  (signed and verified)

MD5:
04ebc6aab4a9fbef353d7b66261ad217

SHA-1:
ad4bb93577600f31d1dfd91acafe44580ed39e56

SHA-256:
344af53585c6bcf971236be1b8417ae6cfa474aaa747fe82d200c68653147e7d

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
12/24/2024 4:27:35 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo (M)
17.3.12.12

File size:
254.2 KB (260,280 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\Program Files\krab web\krabwebuninstall.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
6/9/2014 2:00:00 AM

Valid to:
6/17/2015 2:00:00 PM

Subject:
CN=Krab Web, O=Krab Web, L=Santa Monica, S=California, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0572744C4944FF55FB05A9A82A78D271

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:01 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30CB

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 38, 6F, 44, 00, E8, F1, 2B, 00, 00, A3, 84, 6E, 44, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 30, 9C, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 80, 2E, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, F0, 46, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
22.5 KB (23,040 bytes)

Program Uninstaller
Program name:
Krab Web

Display publisher:
Krab Web

Display version:
2014.08.30.155802

Uninstall string:
C:\Program Files (x86)\Krab Web\KrabWebuninstall.exe


The file krabwebuninstall.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Krab Web  by Yontoo Technology, Inc.
Krab Web is an advertising supported browser extension also known as adware and is designed to deliver ads to the user's Internet browser as banners, context text-links and transitionals ads. The injected ads are not affiliated with the underlying website on which they appear.
krabweb.net/support
81% remove it
 
Powered by Should I Remove It?

Remove krabwebuninstall.exe - Powered by Reason Core Security