utilgreenerweb.exe

Greener Web

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilgreenerweb.exe by Greener Web has been detected as adware by 15 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update Greener Web”. Additionally, the file is typically installed by a number of programs including Greener Web by Yontoo Technology, Inc. and Buzzdock by Alactro LLC, both potentially unwanted software. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Greener Web  (signed and verified)

Version:
1.0.5316.35477

MD5:
3a7fcfe14d0836a5594ad85442b1f9e6

SHA-1:
5e55862bc9b07f04277572d2593d7c8e5626622c

SHA-256:
58921ee88a8ef6cceed3461f2872297598612158004a5c7ee7a3dc2b2f9636cb

Scanner detections:
15 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/23/2024 11:55:24 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.AM
927

AVG
Greenerweb
2015.0.3405

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14723

Bitdefender
Adware.SwiftBrowse.AM
1.0.20.1020

Emsisoft Anti-Malware
Adware.SwiftBrowse.AM
8.14.07.23.10

ESET NOD32
Win32/BrowseFox (variant)
8.10140

F-Secure
Adware.SwiftBrowse.AM
11.2014-23-07_4

G Data
Adware.SwiftBrowse.AM
14.7.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.6.1.0

Kaspersky
not-a-virus:RiskTool.Win32.Agent
14.0.0.3518

Malwarebytes
PUP.Optional.GreenerWeb.A
v2014.07.23.10

McAfee
Artemis!3A7FCFE14D08
5600.7061

MicroWorld eScan
Adware.SwiftBrowse.AM
15.0.0.612

Qihoo 360 Security
Win32/Virus.RiskTool.c91
1.0.0.1015

Reason Heuristics
PUP.GreenerWeb.O
14.7.23.10

File size:
314.3 KB (321,824 bytes)

Product version:
1.0.5316.35477

Original file name:
GreenerWeb.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\greener web\bin\utilgreenerweb.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/21/2014 9:00:00 PM

Valid to:
4/22/2015 8:59:59 PM

Subject:
CN=Greener Web, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Greener Web, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5AE1591EB6D76718ADCE211DFB4D195B

File PE Metadata
Compilation timestamp:
7/22/2014 5:42:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:y3Bn8j1CFS2F7kHsus23wTAHaws7gUFxKeA0pbFV30:y3By1n2FnflxFjLi

Entry address:
0x4E596

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
305.5 KB (312,832 bytes)

Service
Display name:
Update Greener Web

Type:
Win32OwnProcess


The file utilgreenerweb.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Greener Web  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
greenerweb.info/support
80% remove it
 
Powered by Should I Remove It?

Remove utilgreenerweb.exe - Powered by Reason Core Security