pageragesetup.exe

Yontoo Layers Runtime

Theme Your World LLC

This is the installer/setup program for a Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application pageragesetup.exe by Theme Your World has been detected as adware by 9 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software. The file has been seen being downloaded from download.pagerage.com. While running, it connects to the Internet address api.yontoo.com on port 80 using the HTTP protocol.
Publisher:
Yontoo LLC  (signed by Theme Your World LLC)

Product:
Yontoo Layers Runtime

Description:
Installer

Version:
2011.6.3.1125

MD5:
28f35d2ba8ad89ce60588c0784203f4c

SHA-1:
79f1ee4f1a928a4e6cc7c86c1acd70a517398290

SHA-256:
7bd0569692ed06e6124ced541b65d9aaa23572550f37e380170df23b4e17af59

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Bundles the Conduit Toolbar and/or Conduit Search Protect.

Analysis date:
11/23/2024 9:47:47 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/Yontoo.Gen
7.11.102.78

Baidu Antivirus
Trojan.Adware.Win32.Yontoo
4.0.3.141211

Dr.Web
Adware.Siggen.24249
9.0.1.0345

ESET NOD32
Win32/Adware.Yontoo (variant)
8.8793

IKARUS anti.virus
not-a-virus.Adware.Conduit
t3scan.2.0.127

Reason Heuristics
PUP.Installer.ThemeYourWorld.N
14.12.11.10

Rising Antivirus
Trojan.InstallRex!562A
23.00.65.141209

Trend Micro House Call
TROJ_GEN.R47H1J8
7.2.345

VIPRE Antivirus
Yontoo
21422

File size:
653.4 KB (669,080 bytes)

Product version:
1.10.01

Copyright:
Copyright (c) 2011 Yontoo LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\pageragesetup.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
5/9/2011 11:38:01 AM

Valid to:
5/9/2012 11:38:01 AM

Subject:
CN=Theme Your World LLC, O=Theme Your World LLC, L=Carlsbad, S=CA, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
080229C2AD472D

File PE Metadata
Compilation timestamp:
8/19/2010 4:08:13 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:JIcOmj7J7zXs02P4k3Ylvsm2kHumRDk8FVmlz1muPKkc8SLG:dvRzXdm4eY2mWUmlBPKvDLG

Entry address:
0x1627

Entry point:
55, 8B, EC, 81, EC, 58, 0B, 00, 00, 53, 56, 33, DB, 57, 66, 89, 9D, A8, F4, FF, FF, 89, 5D, FC, FF, 15, 74, 30, 40, 00, A3, 00, 40, 40, 00, FF, 15, 70, 30, 40, 00, 89, 45, F8, 8D, 85, B8, FC, FF, FF, 50, C7, 85, B8, FC, FF, FF, 14, 01, 00, 00, FF, 15, 6C, 30, 40, 00, 85, C0, 75, 21, FF, 15, 14, 30, 40, 00, 50, 68, 30, 34, 40, 00, E8, 40, FA, FF, FF, 59, C7, 05, 04, 40, 40, 00, FF, 00, 00, 00, E9, C5, 01, 00, 00, 68, 1C, 34, 40, 00, 68, 0C, 34, 40, 00, FF, 15, 68, 30, 40, 00, 50, FF, 15, 64, 30, 40, 00, 3B...
 
[+]

Entropy:
7.9899

Developed / compiled with:
Microsoft Visual C++

Code size:
7.5 KB (7,680 bytes)

The file pageragesetup.exe has been seen being distributed by the following URL.

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to wac.edgecastcdn.net  (72.21.81.13:80)

TCP (HTTP):
Connects to service.yontoo.com  (8.25.35.148:80)

TCP (HTTP):
Connects to api.yontoo.com  (8.25.35.15:80)

Remove pageragesetup.exe - Powered by Reason Core Security