updategreenerweb.exe

Greener Web

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for Greener Web will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updategreenerweb.exe by Greener Web has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Greener Web”. This file is typically installed with the program Greener Web by Yontoo Technology, Inc. which is a potentially unwanted software program.
Publisher:
Greener Web  (signed and verified)

Version:
1.0.5273.24217

MD5:
d3bd8b5601f65de026a55b4b8891f565

SHA-1:
7a141c35ec5e2b9ceb94b3e2f96c3c9ad3d936df

SHA-256:
a6760f450509df029b7cef3e8be2938ca0d0fe664546b807ea01f8c7a55983e3

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/25/2024 10:58:33 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Yontoo.GreenerWeb (M)
16.1.26.1

File size:
310.3 KB (317,728 bytes)

Product version:
1.0.5273.24217

Original file name:
GreenerWeb.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\greener web\updategreenerweb.exe

Digital Signature
Signed by:

Authority:
DigiCert Inc

Valid from:
6/5/2014 7:00:00 AM

Valid to:
6/10/2015 7:00:00 PM

Subject:
CN=Greener Web, O=Greener Web, L=Santa Monica, S=California, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07CF8E3C70EA58D06FE678225FF74862

File PE Metadata
Compilation timestamp:
6/9/2014 9:27:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:3/YBn8TwefBBVkk4Cz5ze5p2rncJNLuubyQu:3/YBGw6BVFM2rcW0u

Entry address:
0x4D5F2

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, E0, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 50, 00, 00, 00, 5C, E0, 04, 00, 84, 02, 00, 00, 00, 00, 00, 00, 84, 02, 34, 00, 00, 00, 56, 00, 53, 00, 5F, 00, 56, 00, 45, 00, 52, 00, 53, 00, 49, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
301.5 KB (308,736 bytes)

Service
Display name:
Update Greener Web

Type:
Win32OwnProcess


The file updategreenerweb.exe has been discovered within the following programs.

Greener Web  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
greenerweb.info/support
80% remove it
 
Powered by Should I Remove It?

Remove updategreenerweb.exe - Powered by Reason Core Security