yourfileupdater.exe
YourFile Downloader by Via Advertising Group Limited (Signed)
Warning 17 antivirus scanners has detected malware in various versions of yourfileupdater.exe.
Overview
There are 5 versions of yourfileupdater.exe in the wild, the latest version being 1, 0, 0, 4. yourfileupdater.exe is run as a standard windows process with the logged in user's account privileges. The process utilizes the Windows Task Scheduler to automatically launch the file as a process when a user logs into Windows. The average file size is about 299.7 KB. The file is a digitally signed and issued to Via Advertising Group Limited by VeriSign. Some variations of the file have been seen to be installed with the program YourFileDownloader from Via Advertising Group Limited. During the process's lifecycle, the typical CPU resource utilization is about 0.0048% including both foreground and background operations, the average private memory consumption is about 9.16 MB with the maximum memory reaching around 13.03 MB. Addionally, typically read and write I/O disk operations is about 913 Bytes per minute for reads and 0 Bytes per minute for writes.
What is yourfileupdater.exe?
The YourFile Downloader auto updater is a program which runs in the background of Windows and automatically starts up when your PC boots. It checks for software udpates and automatically downloads and installs them if found.
About yourfileupdater.exe (from Via Advertising Group Limited)
“YourFileDownloader is designed to make your download experience easier and quicker than ever. Now you don’t have to spend your valuable time and energy for finding desired programs and get forwarded a”
Details |
File name: | yourfileupdater.exe |
Publisher: | http://yourfiledownloader.com |
Product name: | YourFile Downloader |
Typical file path: | C:\Program Files\yourfiledownloader\yourfileupdater.exe |
Original name: | YourFile.exe |
Certificate |
Issued to: | Via Advertising Group Limited |
Authority (CA): | VeriSign |
Effective date: | Monday, April 30, 2012 |
Expiration date: | Wednesday, May 1, 2013 |
Programs installed in
(Note, the programs listed below are for all versions of YourFile Downloader.)
|
Via Advertising Group Limited |
|
YourFileDownloader provides the ability to download various software applications locally. It provides a list and search interface to locate and download appliations. The program does however automati...
Behaviors
(Note, the behaviors below are for all versions of yourfileupdater.exe, select a unique version for details.)
Scheduled tasks
- The job 'YourFile Update' runs on logon in the path '\YourFile Update'
- The task 'Your File Updater' runs in the path '\Your File Updater'
- The task 'YourFile DownloaderUpdate' runs on logon in the path '\YourFile DownloaderUpdate'
- Entry path 'C:\WINDOWS\Tasks\Your File Updater.job'
- Entry path 'C:\windows\Tasks\YourFile DownloaderUpdate.job'
- Entry path '\YourFile DownloaderUpdate'
- Entry path 'C:\WINDOWS\Tasks\YourFile Update.job'
- Entry path '\YourFile Update'
- Entry path '\Your File Updater'
Scheduled tasks startups
Set to load on user login (bypasses Windows UAC if enabled)
- Login entry path 'C:\WINDOWS\Tasks\Your File Updater.job'
- Login entry path 'C:\windows\Tasks\YourFile DownloaderUpdate.job'
- Login entry path '\YourFile DownloaderUpdate'
- Login entry path 'C:\WINDOWS\Tasks\YourFile Update.job'
- Login entry path '\YourFile Update'
- Login entry path '\Your File Updater'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
- Firewall exception for 'C:\Program Files\YourFileDownloader\YourFileUpdater.exe'
Malware detections
Based on 40+ industry antivirus scanners, 17 of them detected the following malware.
Antivirus engine | Engine version | Detection | File version |
avast! |
8.0.1489.320 |
Win32:Downloader-UEO [PUP] |
1, 0, 0, 4 |
avast! |
8.0.1489.320 |
Win32:Downloader-UEO [PUP] |
1, 0, 0, 4 |
Emsisoft Anti-Malware |
3.0.0.575 |
Trojan.Win32.YourFileDownloader.AMN (A) |
1, 0, 0, 3 |
ESET NOD32 |
7.8227 |
a variant of Win32/YourFileDownloader.B |
1, 0, 0, 3 |
ESET NOD32 |
7.8859 |
a variant of Win32/YourFileDownloader.B |
1, 0, 0, 4 |
ESET NOD32 |
7.8772 |
a variant of Win32/YourFileDownloader.B |
1, 0, 0, 4 |
Kingsoft |
2012.12.21.213 |
Win32.Troj.Agent.(kcloud) |
1.0.0.1 |
Kingsoft |
2013.4.9.267 |
Win32.Troj.Generic.a.(kcloud) |
1, 0, 0, 4 |
nProtect |
2013-01-12.01 |
Trojan/W32.Agent.245168.B |
1.0.0.1 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0621 |
1, 0, 0, 4 |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.F47V0812 |
1, 0, 0, 4 |
VIPRE Antivirus |
14992 |
Via Advertising (fs) |
1.0.0.1 |
VIPRE Antivirus |
16022 |
Via Advertising (fs) |
1.0.0.1 |
VIPRE Antivirus |
16868 |
Via Advertising (fs) |
1, 0, 0, 3 |
VIPRE Antivirus |
21966 |
Via Advertising (fs) |
1, 0, 0, 4 |
VIPRE Antivirus |
21242 |
Via Advertising (fs) |
1, 0, 0, 4 |
ViRobot |
2011.4.7.4223 |
Trojan.Win32.A.Agent.245168 |
1.0.0.1 |
All file variations of yourfileupdater.exe
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate |
36.78% |
|
Windows 7 Home Premium |
24.14% |
|
Microsoft Windows XP |
21.84% |
|
Windows 8 Pro |
6.90% |
|
Windows 7 Professional |
3.45% |
|
Windows 7 Home Basic |
3.45% |
|
Windows 8 |
2.30% |
|
Windows 8 Enterprise |
1.15% |
|
Distribution by country
United States installs about 28.74% of YourFile Downloader.
Distribution by PC manufacturer
PC Manufacturer | distribution |
Hewlett-Packard |
29.27% |
|
Acer |
21.95% |
|
Dell |
19.51% |
|
Sony |
14.63% |
|
GIGABYTE |
4.88% |
|
Toshiba |
4.88% |
|
Alienware |
2.44% |
|
American Megatrends |
2.44% |
|