SquirrelWeb

SquirrelWeb

Known Malware

by Yontoo Technology, Inc.

What is SquirrelWeb?

SquirrelWeb is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 64.46% of installations running this operating system. SquirrelWeb's installer is typically 0.98 MB in size and installs around 5 files. The most common release is 2013.11.19.222532 with 80.17% of all installations currently using this version.

SquirrelWeb is most popular in the United States with 21.81% of installations residing in this country.

About SquirrelWeb?

This software provides a web browser extension that offers search hijacking and contextual advertising within the user's web browser. It is able to modify the user's home and search pages in order to monetize search activities and can install a Browser Helper Object (BHO) in Internet Explorer to monitor and track user web browsing activities and display various banner and link-context ads in addition to its search redirection. The suite of browser features offered by the software customizes and enhances a user's interaction with various websites by rendering graphics, text, or other functional or interactive content in the browser. These features include tools and applications for search, text referencing, video, social media, website ratings and reviews, coupons, and comparison shopping for various products and services, including travel and insurance. Additionally, the software may be used remotely to support computing research programs. It is compatible with Internet Explorer, Firefox, Safari, Google, and Chrome browsers and will be automatically enabled upon restart after installation. The software may also automatically download upgrades, enable new features or functionality, and install fixes without additional notice. It is important to note that the software is supported by various types of advertising, including search, banner, text link, transitional, interstitial, and full-page ads. These ads and features may appear on websites using the software, but they are not associated with or endorsed by the underlying websites. Some features and ad placements may contain links to further information or disabling instructions. All software features, content, and advertising may be updated, modified, added, enabled, disabled, or discontinued at any time automatically and without additional notice to the user.

Multiple virus scanners have detected malware in SquirrelWeb.

updateSquirrelWeb.exe (MD5: 0d8697ac5a6fdfd30042dc233d0a4dd9) has been flagged by 20 scanners:
Scanner Software Result
Agnitum Outpost PUA.Kranet!
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/MSIL.Kranet
AVG Squiweb
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.BH
ESET-NOD32 a variant of Win32/BrowseFox.H
G Data Win32.Trojan.Agent.4FV73O
IKARUS anti.virus PUA.BrowseFox
K7 AntiVirus Trojan ( 0049c6b61 )
K7GW Trojan ( 0049c6b61 )
Kaspersky not-a-virus:HEUR:AdWare.MSIL.Kranet.heur
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.SquirrelWeb.A
McAfee Artemis!0D8697AC5A6F
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.Adware.e4c
Sophos Generic PUA HN
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0810
VIPRE Antivirus Yontoo (fs)
SquirrelWebBHO.dll (MD5: d4e754eab0969b7b13a818ed547fc58e) has been flagged by 29 scanners:
Scanner Software Result
Agnitum Outpost PUA.Agent
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
CAT-QuickHeal AdWare.Agent.ahbx (Not a Virus)
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.28
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
Jiangmin Adware/Agent.jaw
K7 AntiVirus Unwanted-Program
K7GW Unwanted-Program ( 00454f261 )
Kaspersky not-a-virus:AdWare.Win32.Agent
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.Squirrelweb.A
McAfee Artemis!D4E754EAB096
McAfee-GW-Edition Artemis!D4E754EAB096
NANO AntiVirus Riskware.Win32.Agent.cqvnby
Sophos Generic PUA OJ
SUPERAntiSpyware Adware.BrowseFox/Variant
TrendMicro-HouseCall TROJ_GEN.F47V0301
Vba32 AntiVirus AdWare.Agent
AVG Squiweb
AVware Yontoo (fs)
Baidu-International Adware.Win32.BrowseFox.BH
G Data Win32.Trojan.Agent.4FV73O
Panda Antivirus Trj/Chgt.B
Qihoo-360 Win32/Virus.Adware.e4c
Symantec Trojan.ADH.2
VIPRE Antivirus Yontoo (fs)

Software Behaviors

Services:
  • updateSquirrelWeb.exe runs as a service named 'Update SquirrelWeb' (Update SquirrelWeb).

Software Details

URL:
https://squirrelweb.org/support
Support:
https://mailto:
Installation path:
C:\Program Files\SquirrelWeb
Uninstaller:
C:\Program Files\SquirrelWeb\SquirrelWebuninstall.exe
Size:
0.98 MB
Language:
English

SquirrelWeb Executable Details

Primary executable:
SquirrelWebBHO.dll
Name:
SquirrelWeb
Path:
C:\Program Files\SquirrelWeb\SquirrelWebBHO.dll
MD5:
d4e754eab0969b7b13a818ed547fc58e
SHA-1:
SHA-256:
Files installed by SquirrelWeb
File Type Filename MD5
EXE
0b86536bba2a922f5f32ad1792d8a03b
EXE
0d8697ac5a6fdfd30042dc233d0a4dd9
DLL
d4e754eab0969b7b13a818ed547fc58e
EXE
a9f6734aa64ad1d88c01936152cc99dd
EXE
12723b165657517ba3774015fd459335