36655.malware

WindowNetworkManager

enliple Ltd.

The file 36655.malware by enliple has been detected as a potentially unwanted program by 25 anti-malware scanners.
Publisher:
enliple Ltd.  (signed and verified)

Product:
WindowNetworkManager

Version:
7.07

MD5:
4e4dabfc1b625038a394fa1781b1fdbd

SHA-1:
2b7ea80dc828bb28c47cd79d83b79fc5efe8146c

SHA-256:
1cdd8dda78bd9c01e2ccbc796e7a13275022163917b01523d6cd5390284a1299

Scanner detections:
25 / 68

Status:
Potentially unwanted

Analysis date:
4/24/2024 10:51:57 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Graftor
7.1.1

AhnLab V3 Security
PUP/Win32.WindowNM
14.10.28

Avira AntiVirus
TR/Symmi.32897.1
7.11.151.204

AVG
Generic_vb
2015.0.3308

Bkav FE
W32.Clod9ea.Trojan
1.3.0.4959

Comodo Security
ApplicUnwnt
18349

Dr.Web
BACKDOOR.Trojan
9.0.1.0301

ESET NOD32
Win32/AdWare.Kraddare.JC (variant)
8.9857

Fortinet FortiGate
Riskware/Kraddare
10/28/2014

IKARUS anti.virus
Worm.Win32.WBNA
t3scan.1.6.1.0

K7 AntiVirus
Adware
13.178.12212

Kaspersky
Worm.Win32.WBNA
14.0.0.2780

Malwarebytes
Adware.Korad
v2014.10.28.03

McAfee
Artemis!4E4DABFC1B62
5600.6964

NANO AntiVirus
Trojan.Win32.Graftor.cqthaf
0.28.0.58101

nProtect
Adware/W32.Agent.1191784
14.03.06.01

Panda Antivirus
Trj/CI.A
14.10.28.03

Qihoo 360 Security
Win32/Worm.23a
1.0.0.1015

Reason Heuristics
PUP.enliple.M
14.10.28.3

Sophos
Generic PUA EK
4.98

Trend Micro House Call
ADW_KRADDARE
7.2.301

Trend Micro
ADW_KRADDARE
10.465.28

Vba32 AntiVirus
TScope.Trojan.VB
3.12.26.0

VIPRE Antivirus
Trojan.Win32.Generic
29680

XVirus List
Win32.Detected
2.10.28

File size:
1.1 MB (1,191,784 bytes)

Product version:
7.07

Original file name:
WindowNetworkManager.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/26/2013 9:00:00 AM

Valid to:
6/27/2015 8:59:59 AM

Subject:
CN=enliple Ltd., OU=Internet Dept, O=enliple Ltd., L=Guro-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
178A151BFE91D2CFD345640D3EE64736

File PE Metadata
Compilation timestamp:
11/28/2013 1:19:49 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:ojJuN+3iWocEDJW5DZ8b9izyUZMMe2wqmzz22BGlGfQis:pDvcyJW5DZ8b9izyUReElGfQV

Entry address:
0x6A7C

Entry point:
68, BC, 3C, 44, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, C4, 58, 17, D8, D6, 9B, B1, 41, 94, 4C, 58, FD, E9, 7E, 38, 66, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 57, 69, 6E, 64, 6F, 77, 4E, 65, 74, 77, 6F, 72, 6B, 4D, 61, 6E, 61, 67, 65, 72, 00, 3A, 5C, 57, 00, 00, 00, 00, FF, CC, 31, 00, 70, FF, FA, 98, 1F, EC, DA, 44, 4D, BA, D6, 1E, 15, B2, FD, 21, 68, FA, B6, 77, 46, 38, 3F, 0E, 4A, 9C, 78, 3E, 20, E2, 06, 39, 85, 3A, 4F, AD...
 
[+]

Entropy:
5.9264

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
912 KB (933,888 bytes)

Remove 36655.malware - Powered by Reason Core Security