pageragesetup.exe

Yontoo Layers Runtime

Theme Your World LLC

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application pageragesetup.exe by Theme Your World has been detected as adware by 10 anti-malware scanners. This is a setup and installation application and has been known to bundle potentially unwanted software. The file has been seen being downloaded from download.pagerage.com. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Yontoo LLC  (signed by Theme Your World LLC)

Product:
Yontoo Layers Runtime

Description:
Installer

Version:
2011.5.25.1633

MD5:
a4fd4b6834e7d5df137e3ac64c6438f3

SHA-1:
17d6ca52f6bd23f96ddc71fb192f81125452814e

SHA-256:
8cd50ada42b9c7ae6946e7b8bd335d1bb0cc9ec29963273619ceec3dffd1a72a

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
11/27/2024 2:03:00 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Yontoo.Gen
7.11.108.198

Baidu Antivirus
AdWare.Win32.Yontoo
4.0.3.15224

Comodo Security
UnclassifiedMalware
17137

Dr.Web
Adware.Siggen.24249
9.0.1.055

ESET NOD32
Win32/Adware.Yontoo (variant)
9.8944

IKARUS anti.virus
AdWare.Yontoo
t3scan.2.0.127

NANO AntiVirus
Trojan.Win32.Siggen.zkexy
0.26.0.55532

Reason Heuristics
PUP.Installer.Yontoo
15.2.24.10

Rising Antivirus
Trojan.InstallRex!562A
23.00.65.15222

VIPRE Antivirus
Yontoo
22590

File size:
653.4 KB (669,088 bytes)

Product version:
1.10.01

Copyright:
Copyright (c) 2011 Yontoo LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pageragesetup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/9/2011 1:38:01 PM

Valid to:
5/9/2012 1:38:01 PM

Subject:
CN=Theme Your World LLC, O=Theme Your World LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
080229C2AD472D

File PE Metadata
Compilation timestamp:
8/19/2010 6:08:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:TI5Omj764wyhW5CvSfcM/OefEYcd4InZvaqANDNgCY/VCajS:6v64u8s5fEhd4IqxNFYgB

Entry address:
0x1627

Entry point:
55, 8B, EC, 81, EC, 58, 0B, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, A8, F4, FF, FF, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, B8, FC, FF, FF, 50, C7, 85, B8, FC, FF, FF, 14, 01, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, 30, 34, 40, 00, E8, 40, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, C5, 01, 00, 00, 68, 1C, 34, 40, 00, 68, 0C, 34, 40, 00, FF, 15, 68, 30, 40, 00, 50, FF, 15, 64, 30, 40, 00, 3B...
 
[+]

Entropy:
7.9902

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file pageragesetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove pageragesetup.exe - Powered by Reason Core Security