84,488,480 programs installed

Should I remove grassmow?

What percent of users and experts removed it?
80% remove it20% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Reach 0.0005%
Lifespan of installation (until removal)
< 1.15 days
34.03 days >
Average installed length: 17.88 days

Versions

VersionDistribution
2014.11.26.162215 11.11%
2014.11.10.122055 11.11%
2014.10.27.222650 11.11%
2014.10.20.205810 11.11%
2014.10.19.135847 11.11%
2014.10.12.130356 11.11%
2014.10.05.143132 11.11%
2014.09.25.090218 11.11%
2014.09.15.120410 11.11%

grassmow

What is grassmow?

grassmow is a web browser extension that injects display advertising in the user's browser. Ads are displayed in the form of banners and contextual text-links and are both injected in white space areas of the HTML page or over existing ads of the underlying web site. These ads are typically for PC optimization utilities, other bundled malware or other types of malvertising.

About  (from Yontoo Technology)

Enhance the web with grassmow.

Overview

The most common release is 2014.11.26.162215, with over 98% of all installations currently using this version. Upon being installed, the software adds a Windows Service which is designed to run continuously in the background. Manually stopping the service has been seen to cause the program to stop functing properly. It adds a background controller service that is set to automatically run. Delaying the start of this service is possible through the service manager. It adds a Browser Helper Object (BHO) to Internet Explorer. The primary executable is named grassmowbho.dll. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 9 files and is usually about 1.5 MB (1,573,602 bytes).
  • Malware detected in the program
  • Integrates into the web browser
  • Installs a Windows Service
  • Typically distributed through a pay-per-install bundle
  • This program has a poor reputation
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in grassmow.
grassmowbho.dll (04cfaa2d14fd2c8cb16c7a8fbfab2c6f) has been flagged by the following 12 scanners:
Anti-Virus softwareVersionDetection
AVG 2015.0.3285 BrowseFox.F
Avira 7.11.171.244 ADWARE/BrowseFox.Gen2
Comodo Security 19509 Application.Win32.BrowseFox.JM
Dr.Web 9.0.0.0324 Trojan.BPlug.144
ESET-NOD32 8.10414 a variant of Win32/BrowseFox.O
Fortinet FortiGate 11/20/2014 Riskware/BrowseFox
IKARUS anti.virus t3scan.1.7.8.0 AdWare.BrowseFox
Malwarebytes v2014.11.20.02 PUP.Optional.Grassmow.A
McAfee 5600.6941 Artemis!04CFAA2D14FD
McAfee-GW-Edition 7.6941 Artemis
Qihoo-360 1.0.0.1015 HEUR/QVM30.1.Malware.Gen
Sophos 4.98 Generic PUA AE
updategrassmow.exe (26109da74ad8ddeef3ef6472f3d1cc3a) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
avast! 8.0.1489.320 Win32:BrowseFox-CK [PUP]
AVG 14.0.0.4040 Generic.D31
AVware 1.5.0.21 Yontoo (fs)
ESET-NOD32 10619 a variant of MSIL/BrowseFox.H
IKARUS anti.virus T3.1.7.8.0 AdWare.MPlug
Malwarebytes 1.75.0.1 PUP.Optional.Grassmow.A
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V1024
VIPRE Antivirus 34232 Yontoo (fs)
       View all 20 all detections
grassmow has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Displayed publisher: grassmow
URL: grassmow.org/support
Help link: mailto:[email protected]
Installation folder: C:\Program Files\grassmow
Uninstaller: C:\Program Files\grassmow\grassmowuninstall.exe
Estimated size: 1.5 MB

Program filesFiles installed by grassmow

Program module:grassmowbho.dll (Malware detected)
Name:grassmow
Path:C:\Program Files\grassmow\grassmowbho.dll
MD5:04cfaa2d14fd2c8cb16c7a8fbfab2c6f
Additional files:
  • 7za.exe (by Igor Pavlov) - 7-Zip (7-Zip Standalone Console)
  • grassmowUninstall.exe
  • (Malware detected) updategrassmow.exe

Program behaviorsBehaviors exhibited

Internet Explorer BHO
  • grassmowbho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'grassmow' with the class of {dff180a7-25c2-41c7-82d2-1960ce0cc82a}.
Service
  • updategrassmow.exe runs as a service named 'Update grassmow' (Update grassmow).

How do I remove grassmow?

You can uninstall grassmow from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program grassmow, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove grassmow.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by grassmow you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win 10 44%
Win Vista 11%
 
HOW IT RUNS
Windows Service? Yes
(Installs a service)
 
USER ACTIONS
Uninstall it 80%
Keep it 20%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 10 44.44%
Windows 7 33.33%
Windows Vista 22.22%
Which OS releases does it run on?
Windows 7 Home Premium 33.33%
Windows 8.1 33.33%
Windows Vista Home Premiu... 22.22%
Windows 8.1 Connected 11.11%

Distribution by countryGeography

50.00% of installs come from the United States
Which countries install it?
  United States 50.00%
  United Kingdom 21.43%
  Canada 14.29%
  France 14.29%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Toshiba 33.33%
Acer 22.22%
ASUS 11.11%
Sony 11.11%
Hewlett-Packard 11.11%
Packard Bell 11.11%
Common models
TOSHIBA Satellite C850 12.50%
TOSHIBA SATELLITE C50-A-1... 12.50%
Sony VGN-AW41JF_H 12.50%
PACKARD BELL BV IMEDIA J3... 12.50%
HP Pavilion dv9700 Notebo... 12.50%
TOSHIBA SATELLITE C50-B 12.50%

About Yontoo Technology

Yontoo, a subsidiary/alias of ad-hijacker Sambreel, is a publisher of ad-supported web browser extensions designed to inject and display advertisements within the browser.
Publisher URL: www.yontoo.com

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.