WebSpades

WebSpades

Known Adware

by Yontoo Technology, Inc.

What is WebSpades?

WebSpades is software application developed by Yontoo Technology, Inc.. It is most commonly found on computers running Windows 7 with nearly 55.44% of installations running this operating system. WebSpades's installer is typically 2.00 MB in size and installs around 18 files. The most common release is 2014.09.03.132603 with 0.41% of all installations currently using this version.

WebSpades is most popular in the United States with 10.43% of installations residing in this country.

About WebSpades?

WebSpades is a browser extension developed and distributed by Yontoo, a division of Sambreel Holdings based in Carlsbad, California. It is designed to integrate with web browsers such as Chrome, Internet Explorer, and Firefox, and inject various forms of advertising, including inline text, multi-site searching, comparison shopping popups, banners, and popups/popunders. This adware application is often included as part of a download bundle and installs itself without notice. In addition to displaying ads, WebSpades also modifies the browser's settings to facilitate its ad injection offers. This includes automatically adjusting the load time in Internet Explorer and modifying the browser's Instant Search feature. Additionally, the adware extension will open search engine results page links in a new browser tab. WebSpades is known for its association with unwanted software and may not be in compliance with standard user privacy and security policies.

Multiple virus scanners have detected malware in WebSpades.

updateWebSpades.exe (MD5: 7b51581a5dfc528298d8ed8d09388dc3) has been flagged by 38 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.SwiftBrowse.CO
AhnLab-V3 Win-PUP/BrowseFox.Gen
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.SwiftBrowse
avast! Win32:BrowseFox-EX [PUP]
AVG Webpade
Avira Adware/BrowseFox.aow
AVware Yontoo (fs)
Baidu-International Adware.MSIL.BrowseFox.H
Bitdefender Adware.SwiftBrowse.CO
CAT-QuickHeal AdWare.Swiftbrowse.r3 (Not a Virus)
Comodo Security ApplicUnwnt
Cyren W32/S-7b6eb46a!Eldorado
Dr.Web Trojan.Yontoo.1070
Emsisoft Anti-Malware Adware.SwiftBrowse.CO (B)
ESET-NOD32 a variant of MSIL/BrowseFox.H potentially unwanted
Fortinet FortiGate Adware/SwiftBrowse
F-Prot W32/S-7b6eb46a!Eldorado
F-Secure Adware.SwiftBrowse.CO
G Data Adware.SwiftBrowse.CO
Jiangmin AdWare/SwiftBrowse.jfk
K7 AntiVirus Unwanted-Program ( 0040f96c1 )
K7GW Unwanted-Program ( 0040f96c1 )
Kaspersky not-a-virus:AdWare.Win32.SwiftBrowse.cj
McAfee BrowseFox-FTQ
McAfee-GW-Edition BehavesLike.Win32.Backdoor.hm
MicroWorld-eScan Adware.SwiftBrowse.CO
NANO AntiVirus Riskware.Win32.SwiftBrowse.dlhlyn
nProtect Adware.SwiftBrowse.CO
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Virus.Adware.dbb
Sophos Generic PUA CB
Symantec Trojan.Gen.2
Tencent Win32.Trojan.Falsesign.Airx
Trend Micro TROJ_GEN.R047C0EA815
TrendMicro-HouseCall TROJ_GEN.R047C0EA815
Vba32 AntiVirus AdWare.SwiftBrowse
VIPRE Antivirus Yontoo (fs)
Zillya Adware.SwiftBrowse.Win32.1216
WebSpadesBHO.dll (MD5: 8514f522de6709d44e7cc7bb7c709343) has been flagged by 44 scanners:
Scanner Software Result
Agnitum Outpost PUA.Agent
Avira AntiVir APPL/BrowseFox.Gen2
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.Agent
Comodo Security Application.Win32.Altbrowse.AK
Dr.Web Trojan.BPlug.17
ESET-NOD32 a variant of Win32/BrowseFox.F
Fortinet FortiGate Adware/Agent
G Data Win32.Application.BrowseFox
IKARUS anti.virus not-a-virus:AdWare.Win32.Agent
Kaspersky not-a-virus:AdWare.Win32.Agent
Kingsoft AntiVirus Win32.Troj.Agent.ah.(kcloud)
Malwarebytes PUP.Optional.WebSpades.A
McAfee Artemis!8514F522DE67
McAfee-GW-Edition Artemis!8514F522DE67
NANO AntiVirus Riskware.Win32.Agent.crkvek
Sophos Generic PUA OH
SUPERAntiSpyware Adware.BrowseFox/Variant
VIPRE Antivirus Yontoo (fs)
Lavasoft Ad-Aware Adware.SwiftBrowse.CO
AhnLab-V3 Win-PUP/BrowseFox.Gen
avast! Win32:BrowseFox-EX [PUP]
AVG Webpade
Avira Adware/BrowseFox.aow
AVware Yontoo (fs)
Baidu-International Adware.MSIL.BrowseFox.H
Bitdefender Adware.SwiftBrowse.CO
CAT-QuickHeal AdWare.Swiftbrowse.r3 (Not a Virus)
Cyren W32/S-7b6eb46a!Eldorado
Emsisoft Anti-Malware Adware.SwiftBrowse.CO (B)
F-Prot W32/S-7b6eb46a!Eldorado
F-Secure Adware.SwiftBrowse.CO
Jiangmin AdWare/SwiftBrowse.jfk
K7 AntiVirus Unwanted-Program ( 0040f96c1 )
K7GW Unwanted-Program ( 0040f96c1 )
MicroWorld-eScan Adware.SwiftBrowse.CO
nProtect Adware.SwiftBrowse.CO
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Virus.Adware.dbb
Symantec Trojan.Gen.2
Tencent Win32.Trojan.Falsesign.Airx
Trend Micro TROJ_GEN.R047C0EA815
TrendMicro-HouseCall TROJ_GEN.R047C0EA815
Vba32 AntiVirus AdWare.SwiftBrowse
Zillya Adware.SwiftBrowse.Win32.1216

Software Behaviors

Services:
  • updateWebSpades.exe runs as a service named 'Update WebSpades' (Update WebSpades).
  • utilWebSpades.exe runs as a service named 'Util WebSpades' (Util WebSpades).

Software Details

URL:
https://webspades.info/support
Support:
https://mailto:
Installation path:
C:\Program Files\WebSpades
Uninstaller:
C:\Program Files\WebSpades\WebSpadesuninstall.exe
Size:
2.00 MB
Language:
English

WebSpades Executable Details

Primary executable:
WebSpadesBHO.dll
Name:
WebSpades
Path:
C:\Program Files\WebSpades\WebSpadesBHO.dll
MD5:
8514f522de6709d44e7cc7bb7c709343
SHA-1:
–
SHA-256:
–
Files installed by WebSpades
File Type Filename MD5
EXE
e92604e043f51c604b6d1ac3bcd3a202
EXE
c5bc3d856c77bc50fb4f06591205e1b1
EXE
8d31becb8cb931c69008858a565afb28
EXE
0446fe39b6c32f64bf64681a20247203
EXE
93196e6549178ec467ef3aa27c8330d5
EXE
7b51581a5dfc528298d8ed8d09388dc3
EXE
83f7bfd26a9f88fe097042e48c455687
DLL
8514f522de6709d44e7cc7bb7c709343
DLL
8514f522de6709d44e7cc7bb7c709343
DLL
8514f522de6709d44e7cc7bb7c709343