websparkleuntemp.exe

WebSparkle

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application websparkleuntemp.exe by WebSparkle has been detected as adware by 6 anti-malware scanners. Additionally, the file is typically installed by a number of programs including Buzzdock by Alactro LLC and WebSparkle 1.0.0 by Yontoo Technology, Inc., both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
WebSparkle  (signed and verified)

Version:
1.0.0.0

MD5:
ffce7b6c45ccd37143d0ddfc9fe13792

SHA-1:
122e71305d854f43204e76a5966a966267303606

SHA-256:
b80d61f58a558d09baf0af3a74d503c844db59ea58d2c15db6bf4f0887179497

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
11/27/2024 1:15:45 AM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2015.0.3423

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.1474

Dr.Web
Trojan.BPlug.95
9.0.1.0185

ESET NOD32
MSIL/BrowseFox (variant)
8.10046

Reason Heuristics
PUP.WebSparkle.Q
14.8.7.21

VIPRE Antivirus
Yontoo
30956

File size:
530.8 KB (543,520 bytes)

Product version:
1.0.0.0

Original file name:
WebSparkle Uninstaller.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\websparkleuntemp.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/13/2013 2:00:00 AM

Valid to:
8/14/2015 1:59:59 AM

Subject:
CN=WebSparkle, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WebSparkle, L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36202DE0CBDFE10F57978E3766DB2ED4

File PE Metadata
Compilation timestamp:
6/17/2014 6:58:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:0AHWGZ9+i5Efuc2j2yHDgLnipkWVscHou8+OTgHvQuU9aCSoUNwr+bmIoAnoF:0AhQC7gW46oukpU+1vF

Entry address:
0x82B06

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0902

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
515 KB (527,360 bytes)

The file websparkleuntemp.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
WebSparkle 1.0.0  by Yontoo Technology, Inc.
WebSparkle is an adware web browser extension designed to take control of the user's browser in order to redirect web searches and inject advertising. In Internet Explorer the program run as a Browser Helper Object.
websparkle.biz/support
79% remove it
 
Powered by Should I Remove It?

The file websparkleuntemp.exe has been seen being distributed by the following URL.

Remove websparkleuntemp.exe - Powered by Reason Core Security