updater.exe

The application updater.exe has been detected as a potentially unwanted program by 21 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “UpdaterSvcGreenerWeb”. This file is typically installed with the program Greener Web by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Version:
1.0.0.3

MD5:
23c22d09d63da6822a647613a0d3bc76

SHA-1:
e94219f382ef5a6aafffaf65aca44758ffcdde49

SHA-256:
f98f2ef3c63c0801bc348b9acdd7f0da35119872f321a3b8fd261c4173309780

Scanner detections:
21 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/16/2024 5:06:21 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Generic.11395861
865

Agnitum Outpost
Riskware.Agent
7.1.1

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14922

Bitdefender
Trojan.Generic.11395861
1.0.20.1325

Dr.Web
Trojan.BPlug.90
9.0.1.0265

Emsisoft Anti-Malware
Trojan.Generic.11395861
8.14.09.22.02

ESET NOD32
Win32/BrowseFox
8.10337

Fortinet FortiGate
Riskware/BrowseFox
9/22/2014

F-Secure
Trojan.Generic.11395861
11.2014-22-09_2

G Data
Trojan.Generic.11395861
14.9.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

K7 AntiVirus
Trojan
13.183.13198

McAfee
Artemis!B79C1B46C1C8
5600.6999

MicroWorld eScan
Trojan.Generic.11395861
15.0.0.795

NANO AntiVirus
Trojan.Win32.BPlug.dbonrn
0.28.2.61861

nProtect
Trojan.Generic.11395861
14.08.29.01

Panda Antivirus
Trj/CI.A
14.09.22.02

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.22.14

Rising Antivirus
PE:Trojan.Win32.Generic.170C5DF9!386686457
23.00.65.14920

Sophos
Generic PUA MG
4.98

Trend Micro House Call
TROJ_GEN.R002H09GR14
7.2.265

File size:
107 KB (109,568 bytes)

Product version:
1.0.0.3

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\greener web\updater.exe

File PE Metadata
Compilation timestamp:
5/30/2014 11:19:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
1536:IePTx35AX//J2GYRzNaL4M80jmwGd4gccoAeEYHCEsWjcdD4KIpTJeyiH:hZ+2y8amZFWTDirDTIpTJepH

Entry address:
0x836B

Entry point:
E8, 8D, 4B, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, 28, 69, 41, 00, E8, 8F, 00, 00, 00, FF, 35, FC, 96, 41, 00, FF, 15, 6C, 11, 41, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 01, 00, 00, 00, CC, 6A, 08, 68, 08, 69, 41, 00, E8, 57, 00, 00, 00, E8, 0C, 32, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 9F, 4C, 00, 00, CC, E8, E4, 31, 00, 00, 8B, 40, 7C, 85, C0...
 
[+]

Entropy:
6.0507

Code size:
63.5 KB (65,024 bytes)

Service
Display name:
UpdaterSvcGreenerWeb

Type:
Win32OwnProcess

Depends on:
RPCSS


The file updater.exe has been discovered within the following program.

Greener Web  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
greenerweb.info/support
80% remove it
 
Powered by Should I Remove It?

Remove updater.exe - Powered by Reason Core Security