updatesmarterpower.exe

SmarterPower

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for SmarterPower will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatesmarterpower.exe by SmarterPower has been detected as adware by 9 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update SmarterPower”. Additionally, the file is typically installed by a number of programs including SmarterPower by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
SmarterPower  (signed and verified)

Version:
1.0.5411.18934

MD5:
5291ac10e058de9de238cd8e251b2bbb

SHA-1:
6bbb12072170a487b7acdc5fe9c95d3e09a91090

SHA-256:
5e3f77c69cd8ae82e592115ff0d8e2bed2c7d9fe567f3031069ac2ae8d1254d2

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/25/2024 4:51:42 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:BrowseFox-CK [PUP]
2014.9-141025

AVG
Generic
2015.0.3310

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.141025

ESET NOD32
MSIL/BrowseFox (variant)
8.10620

IKARUS anti.virus
PUA.SwiftBrowse
t3scan.1.7.8.0

Malwarebytes
PUP.Optional.SmarterPower.A
v2014.10.25.05

Reason Heuristics
Adware.Yontoo.Service.S
14.10.25.17

Sophos
Browse Fox
4.98

VIPRE Antivirus
Yontoo
34232

File size:
511.2 KB (523,512 bytes)

Product version:
1.0.5411.18934

Original file name:
SmarterPower.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\smarterpower\updatesmarterpower.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2014 8:00:00 PM

Valid to:
8/5/2015 7:59:59 PM

Subject:
CN=SmarterPower, O=SmarterPower, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38D7C83A73CB4E3AC85648608E3170D8

File PE Metadata
Compilation timestamp:
10/25/2014 2:31:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:DUeFfH1XEWhXITI+nAsVip0NA4KQkOU5o:Dj5E8qA4KQke

Entry address:
0x7F93E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 5F, 00, 00, 00, 80, F9, 07, 00, 80, DB, 07, 00, 52, 53, 44, 53, 9D, DC, 9A, FD, D0, 51, F4, 43, B4, 44, 67, 5A, FD, FD, 21, C6, 01, 00, 00, 00, 44, 3A, 5C, 55, 74, 69, 6C, 69, 74, 69, 65, 73, 5C, 74, 73, 79, 34, 69, 62, 32, 31, 2E, 73, 35, 61, 5C, 44, 65, 73, 6B, 74, 6F, 70, 5C, 44, 65, 73, 6B...
 
[+]

Entropy:
5.9432

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
502.5 KB (514,560 bytes)

Service
Display name:
Update SmarterPower

Type:
Win32OwnProcess


The file updatesmarterpower.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
SmarterPower  by Yontoo Technology, Inc.
SmarterPower is an advertising supported browser extension also known as adware and is designed to deliver ads to the user's Internet browser as banners, context text-links and transitionals ads. The injected ads are not affiliated with the underlying website on which they appear.
smarterpowerunite.com/support
87% remove it
 
Powered by Should I Remove It?

Remove updatesmarterpower.exe - Powered by Reason Core Security