utilgreenerweb.exe

Greener Web

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilgreenerweb.exe by Greener Web has been detected as adware by 17 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update Greener Web”. This file is typically installed with the program Greener Web by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Greener Web  (signed and verified)

Version:
1.0.5353.22132

MD5:
a95e088333cb8c40f17a31bb6076837a

SHA-1:
66a4a5a3edcaffd88f8910a6e1c858c23d40004e

SHA-256:
de3fb095f26de02931dfbfe8b9558a7febf8f935e23ac88639c59d19e7294adf

Scanner detections:
17 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/23/2024 8:59:24 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.AM
890

AVG
Greenerweb
2015.0.3368

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14828

Bitdefender
Adware.SwiftBrowse.AM
1.0.20.1200

Emsisoft Anti-Malware
Adware.SwiftBrowse.AM
9.0.0.4324

ESET NOD32
Win32/BrowseFox.H potentially unwanted application
7.0.302.0

F-Secure
Adware.SwiftBrowse.AM
11.2014-28-08_5

G Data
Adware.SwiftBrowse.AM
14.8.24

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.7.5.0

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3335

Malwarebytes
PUP.Optional.GreenerWeb.A
v2014.08.28.11

MicroWorld eScan
Adware.SwiftBrowse.AM
15.0.0.720

nProtect
Adware.SwiftBrowse.AM
14.08.28.01

Panda Antivirus
Trj/CI.A
14.08.28.11

Qihoo 360 Security
Win32/Virus.Adware.e4c
1.0.0.1015

Reason Heuristics
PUP.GreenerWeb.O
14.8.28.22

VIPRE Antivirus
Threat.4741131
32210

File size:
315.8 KB (323,360 bytes)

Product version:
1.0.5353.22132

Original file name:
GreenerWeb.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\greener web\bin\utilgreenerweb.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/21/2014 5:00:00 PM

Valid to:
4/22/2015 4:59:59 PM

Subject:
CN=Greener Web, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Greener Web, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5AE1591EB6D76718ADCE211DFB4D195B

File PE Metadata
Compilation timestamp:
8/28/2014 6:18:01 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:/h8fAzkAfxgUba0y7U/td7hk6KwOOxhx9R7MXPUVv0ZLtw6FXbg5:/h8fVaPxxEiSU5

Entry address:
0x4EBBE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 00, 10, 00, 00, 00, 20, 00, 00, 80, 18, 00, 00, 00, E0, 02, 00, 80, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 01, 00, 01, 00, 00, 00, 38, 00, 00, 80, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0943

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
307 KB (314,368 bytes)

Service
Display name:
Update Greener Web

Type:
Win32OwnProcess


The file utilgreenerweb.exe has been discovered within the following programs.

Buzzdock  by Alactro LLC
This is a web browser extension that injects advertising. From the EULA: "Buzzdock is free to download and use. Buzzdock is supported by advertising, and users will see additional ads on websites where Buzzdock features operate.
www.buzzdock.com/faq-support
79% remove it
Greener Web  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
greenerweb.info/support
80% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):

TCP (HTTP):
Connects to a23-50-181-163.deploy.static.akamaitechnologies.com  (23.50.181.163:80)

TCP (HTTP):
Connects to a104-96-90-192.deploy.static.akamaitechnologies.com  (104.96.90.192:80)

Remove utilgreenerweb.exe - Powered by Reason Core Security