greenerwebbho.dll

Greener Web

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module greenerwebbho.dll by Greener Web has been detected as adware by 30 anti-malware scanners. It is installed within the context of Internet Explore as a BHO (Browser Helper Object) under the name ‘Greener Web’. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Greener Web  (signed and verified)

Product:
Greener Web

Version:
1.0.0.3

MD5:
80f0429cea4f8761b76370f442e4aa64

SHA-1:
fbf1acd15da9000fba93f859682fff6571477c1f

SHA-256:
30b451d79e68f29aabfdfcb8dcaca23c934441de5a03f77e17d34a963b9d6b72

Scanner detections:
30 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/24/2024 5:52:54 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.AM
827

Agnitum Outpost
PUA.Agent
7.1.1

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.175.48

AVG
BrowseFox.F
2015.0.3305

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.141031

Bitdefender
Adware.SwiftBrowse.AM
1.0.20.1520

Comodo Security
Application.Win32.BrowseFox.JM
19651

Dr.Web
Trojan.BPlug.142
9.0.1.0304

Emsisoft Anti-Malware
Adware.SwiftBrowse.AM
8.14.10.31.07

ESET NOD32
Win32/BrowseFox (variant)
8.10480

Fortinet FortiGate
Adware/Agent
10/31/2014

F-Secure
Adware.SwiftBrowse.AM
11.2014-31-10_6

G Data
Adware.SwiftBrowse.AM
14.10.24

IKARUS anti.virus
AdWare.BHO
t3scan.1.6.1.0

K7 AntiVirus
Unwanted-Program
13.180.12463

Kaspersky
not-a-virus:AdWare.Win32.Agent
14.0.0.3019

Malwarebytes
PUP.Optional.GreenerWeb.A
v2014.10.31.07

McAfee
BrowseFox
5600.6961

MicroWorld eScan
Adware.SwiftBrowse.AM
15.0.0.912

NANO AntiVirus
Trojan.Win32.BPlug.dedpsr
0.28.2.62286

nProtect
Adware.SwiftBrowse.AM
14.09.28.01

Panda Antivirus
Trj/CI.A
14.10.31.07

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Adware.Yontoo.BHO.N
14.10.31.6

Sophos
Generic PUA PL
4.98

SUPERAntiSpyware
Adware.BrowseFox/Variant
10266

Trend Micro House Call
Suspicious_GEN.F47V0617
7.2.304

Vba32 AntiVirus
AdWare.Agent
3.12.26.3

VIPRE Antivirus
Yontoo
33520

Zillya! Antivirus
Adware.Agent.Win32.9168
2.0.0.1832

File size:
244.8 KB (250,656 bytes)

Product version:
1.0.0.3

Copyright:
(c) Greener Web. All rights reserved.

Original file name:
Greener WebIEClient.dll

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\greener web\greenerwebbho.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/22/2014 8:00:00 AM

Valid to:
4/23/2015 7:59:59 AM

Subject:
CN=Greener Web, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Greener Web, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5AE1591EB6D76718ADCE211DFB4D195B

File PE Metadata
Compilation timestamp:
9/27/2014 4:48:56 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:pKxo+LwmiPxfIz+i0yvM3aDJmd15+TxIaI7EqcUzY:pgLwmiZfa+iokxI4HUzY

Entry address:
0x12854

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, 41, 8D, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, 90, 30, 03, 10, E8, BD, 01, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 24, 78, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, 1C, A5, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.3534

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

Internet Explorer BHO
Display name:
Greener Web

CLSID:
{1973d53b-7311-45d7-8270-f44571c041a0}


Remove greenerwebbho.dll - Powered by Reason Core Security