updater.exe

The application updater.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “UpdaterSvcGreenerWeb”. This file is typically installed with the program Greener Web by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Version:
1.0.0.3

MD5:
405a324faad64813cb6f21ab4da2fe0e

SHA-1:
3b3e13edcde9edad096d1aa3c069c1a94798146c

SHA-256:
8f1843f11cc6fc94a59c8137bd5959ed40493baa1afd17a81cf8acd2de6f2b9a

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/27/2024 3:26:19 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11395861
865

Agnitum Outpost
Riskware.Agent
7.1.1

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14922

Bitdefender
Trojan.Generic.11395861
1.0.20.1325

Dr.Web
Trojan.BPlug.90
9.0.1.0265

Emsisoft Anti-Malware
Trojan.Generic.11395861
8.14.09.22.02

ESET NOD32
Win32/BrowseFox
8.10337

Fortinet FortiGate
Riskware/BrowseFox
9/22/2014

F-Secure
Trojan.Generic.11395861
11.2014-22-09_2

G Data
Trojan.Generic.11395861
14.9.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13198

McAfee
Artemis!B79C1B46C1C8
5600.6999

MicroWorld eScan
Trojan.Generic.11395861
15.0.0.795

NANO AntiVirus
Trojan.Win32.BPlug.dbonrn
0.28.2.61861

nProtect
Trojan.Generic.11395861
14.08.29.01

Panda Antivirus
Trj/CI.A
14.09.22.02

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.14

Rising Antivirus
PE:Trojan.Win32.Generic.170C5DF9!386686457
23.00.65.14920

Sophos
Generic PUA MG
4.98

Trend Micro House Call
TROJ_GEN.R002H09GR14
7.2.265

File size:
107 KB (109,568 bytes)

Product version:
1.0.0.3

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\greener web\updater.exe

File PE Metadata
Compilation timestamp:
6/6/2014 8:22:19 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:tePTx35AX//J2GYRzNaL4M80jmwGd4gccoAeEYHCEsWjcdR4KIpTJeyTH:YZ+2y8amZ9WTDirRTIpTJeMH

Entry address:
0x836B

Entry point:
E8, 8D, 4B, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, 28, 69, 41, 00, E8, 8F, 00, 00, 00, FF, 35, FC, 96, 41, 00, FF, 15, 6C, 11, 41, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 01, 00, 00, 00, CC, 6A, 08, 68, 08, 69, 41, 00, E8, 57, 00, 00, 00, E8, 0C, 32, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 9F, 4C, 00, 00, CC, E8, E4, 31, 00, 00, 8B, 40, 7C, 85, C0...
 
[+]

Code size:
63.5 KB (65,024 bytes)

Service
Display name:
UpdaterSvcGreenerWeb

Type:
Win32OwnProcess

Depends on:
RPCSS


The file updater.exe has been discovered within the following programs.

Greener Web  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
greenerweb.info/support
80% remove it
 
Powered by Should I Remove It?

Remove updater.exe - Powered by Reason Core Security