{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys

Greener Web

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The file {a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys by Greener Web has been detected as adware by 6 anti-malware scanners. It runs as a Windows 64-bit kernel mode device driver named “{a3f28269-ad17-41a8-b032-3e0313ef8979}w64”. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
StdLib  (signed by Greener Web)

Product:
StdLib

Version:
1.4.3.1 built by: WinDDK

MD5:
2ff0acaaaaea4c93ef8b3ccf45c817a8

SHA-1:
5d82761187056ffa0b1068151888dc943b933398

SHA-256:
be848ab4b583d50ee00da3253b856d8ad972c95ad44df581603e0b2dd5117cba

Scanner detections:
6 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/25/2024 11:13:50 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AVG
Greeneb
2015.0.3410

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14717

IKARUS anti.virus
AdWare.SpadeCast
t3scan.1.6.1.0

Reason Heuristics
PUP.GreenerWeb.m
14.7.17.14

Sophos
BrowseSmart
4.98

VIPRE Antivirus
Threat.4150696
31208

File size:
59.6 KB (61,016 bytes)

Product version:
1.4.3.1

Copyright:
Copyright © 2013 StdLib

Original file name:
StdLib.sys

File type:
Driver (Win64 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\{a3f28269-ad17-41a8-b032-3e0313ef8979}w64.sys

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
6/5/2014 3:00:00 AM

Valid to:
6/10/2015 3:00:00 PM

Subject:
CN=Greener Web, O=Greener Web, L=Santa Monica, S=California, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07CF8E3C70EA58D06FE678225FF74862

File PE Metadata
Compilation timestamp:
1/31/2014 2:45:30 AM

OS version:
6.1

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
768:Sot2dxF9O8ZF33iqiIy938bWp9XcfBvJkowidIx4w2GMIf:S9JRicy938ip9ea1jmwoIf

Entry address:
0xF064

Entry point:
48, 83, EC, 28, 4C, 8B, C2, 4C, 8B, C9, E8, 95, FF, FF, FF, 49, 8B, D0, 49, 8B, C9, 48, 83, C4, 28, E9, 2E, 20, FF, FF, CC, CC, 38, F2, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 1C, F6, 00, 00, 60, C1, 00, 00, 28, F1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, BE, F9, 00, 00, 50, C0, 00, 00, D8, F0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, B6, FA, 00, 00, 00, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 9A, FA, 00, 00, 00, 00, 00, 00, 86, FA, 00, 00...
 
[+]

Code size:
46.5 KB (47,616 bytes)

Driver
Display name:
{a3f28269-ad17-41a8-b032-3e0313ef8979}w64

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI