utilgreenerweb.exe

Greener Web

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The application utilgreenerweb.exe by Greener Web has been detected as adware by 38 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Update Greener Web”. This file is typically installed with the program Greener Web by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Greener Web  (signed and verified)

Version:
1.0.5378.25858

MD5:
6c747b070ef43c0f960715f244b76901

SHA-1:
ef0c14aade4e56b03e02c17b7fa38786700a9e4a

SHA-256:
cc335227ecdc1fd72e234da020683a45f68448cce4dfe3a4ef5a526c6d694fbb

Scanner detections:
38 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/26/2024 10:08:10 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.SwiftBrowse.AM
864

AhnLab V3 Security
PUP/Win32.SwiftBrowse
2014.11.01

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.182.172

avast!
Win32:BrowseFox-CD [PUP]
2014.9-141205

AVG
Greenerweb
2015.0.3342

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.14923

Bitdefender
Adware.SwiftBrowse.AM
1.0.20.1330

Comodo Security
ApplicUnwnt
19960

Dr.Web
Trojan.BPlug.250
9.0.1.0339

Emsisoft Anti-Malware
Adware.SwiftBrowse.AM
8.14.09.23.12

ESET NOD32
Win32/BrowseFox (variant)
8.10653

Fortinet FortiGate
Adware/Kranet
12/5/2014

F-Secure
Adware.SwiftBrowse.AM
11.2014-23-09_3

G Data
Adware.SwiftBrowse.AM
14.9.24

herdProtect (fuzzy)
2014.12.5.15

IKARUS anti.virus
PUA.BrowseFox
t3scan.1.8.3.0

K7 AntiVirus
Trojan
13.185.13866

Kaspersky
not-a-virus:HEUR:AdWare.MSIL.Kranet
14.0.0.3207

Malwarebytes
PUP.Optional.GreenerWeb.A
v2014.09.23.12

McAfee
BrowseFox.c
5600.6926

MicroWorld eScan
Adware.SwiftBrowse.AM
15.0.0.798

nProtect
Adware.SwiftBrowse.AM
14.10.31.01

Qihoo 360 Security
Win32/Virus.Adware.e4c
1.0.0.1015

Quick Heal
AdWare.MSIL.r3 (Not a Virus)
12.14.14.00

Reason Heuristics
PUP.Service.GreenerWeb.O
14.9.23.12

Sophos
Generic PUA EF
4.98

Trend Micro House Call
TROJ_GEN.R0C1C0EJM14
7.2.339

Trend Micro
TROJ_GEN.R0C1C0EJM14
10.465.05

VIPRE Antivirus
Yontoo
34422

Zillya! Antivirus
Backdoor.PePatch.Win32.48867
2.0.0.1973

File size:
317.8 KB (325,408 bytes)

Product version:
1.0.5378.25858

Original file name:
GreenerWeb.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\greener web\bin\utilgreenerweb.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/22/2014 2:00:00 AM

Valid to:
4/23/2015 1:59:59 AM

Subject:
CN=Greener Web, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Greener Web, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5AE1591EB6D76718ADCE211DFB4D195B

File PE Metadata
Compilation timestamp:
9/22/2014 5:22:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:gfS/h4gw/dYRDxqI41PWvTsXPN+CQuKgZB3WvSl2VTFsg67g86OdTQtHu7JKroIs:gfS/nL23v4v678u4Rgj

Entry address:
0x4F33A

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
309 KB (316,416 bytes)

Service
Display name:
Update Greener Web

Type:
Win32OwnProcess


The file utilgreenerweb.exe has been discovered within the following program.

Greener Web  by Yontoo Technology, Inc.
This adware software (a branded version of the morphing Yontoo adware browser addon) injects itself into the user's web browser (IE, Chrome and Firefox) and will display out-of context advertising on web sites that are not associated with Yontoo or its affiliate partners.
greenerweb.info/support
80% remove it
 
Powered by Should I Remove It?

Remove utilgreenerweb.exe - Powered by Reason Core Security