updatesmarterpower.exe

SmarterPower

Part of the Yontoo web browser plugin (delivers advertisements to the web browser in the form of injected banners, text-links, popups, etc.) the updater mechanism for SmarterPower will automatically keep the extension patched by downloaded new functionality which is auto-enabled by default. The application updatesmarterpower.exe by SmarterPower has been detected as adware by 15 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update SmarterPower”. This file is typically installed with the program SmarterPower by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
SmarterPower  (signed and verified)

Version:
1.0.5371.15396

MD5:
e272f4f2032ee0872ea27d2a3daa32f5

SHA-1:
de5fabac1a586841eaa37f3df8436085a448d6bb

SHA-256:
ab54f0b31292f4c132ec14091affe8324c04a900e449ed21b10b49d66a55f427

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Part of the Yontoo adware web browser extension update process.

Analysis date:
4/23/2024 8:45:55 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.173.22

avast!
Win32:BrowseFox-AN [PUP]
2014.9-140920

AVG
Generic
2015.0.3345

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14920

Comodo Security
ApplicUnwnt
19547

ESET NOD32
Win32/BrowseFox (variant)
8.10437

Fortinet FortiGate
Adware/Kranet
9/20/2014

K7 AntiVirus
Riskware
13.183.13407

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3220

Malwarebytes
PUP.Optional.SmarterPower.A
v2014.09.20.10

McAfee
Artemis!E272F4F2032E
5600.7001

Panda Antivirus
Trj/Chgt.F
14.09.20.10

Qihoo 360 Security
Win32/Virus.Adware.e4c
1.0.0.1015

Reason Heuristics
Adware.Yontoo.Service.S
14.9.20.22

VIPRE Antivirus
Yontoo
33224

File size:
315.7 KB (323,320 bytes)

Product version:
1.0.5371.15396

Original file name:
SmarterPower.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\smarterpower\updatesmarterpower.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
8/4/2014 9:00:00 PM

Valid to:
8/5/2015 8:59:59 PM

Subject:
CN=SmarterPower, O=SmarterPower, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
38D7C83A73CB4E3AC85648608E3170D8

File PE Metadata
Compilation timestamp:
9/15/2014 6:33:29 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:pFfAzP3pq46jSYm7Ip/d7FuuDBfHvYQ1S/p8r47Xb15sk:pFfeZkpvl1SirKJ5N

Entry address:
0x4EBAA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, E8, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
307 KB (314,368 bytes)

Service
Display name:
Update SmarterPower

Type:
Win32OwnProcess


The file updatesmarterpower.exe has been discovered within the following program.

SmarterPower  by Yontoo Technology, Inc.
SmarterPower is an advertising supported browser extension also known as adware and is designed to deliver ads to the user's Internet browser as banners, context text-links and transitionals ads. The injected ads are not affiliated with the underlying website on which they appear.
smarterpowerunite.com/support
87% remove it
 
Powered by Should I Remove It?

Remove updatesmarterpower.exe - Powered by Reason Core Security