passshow_wd.exe

The application passshow_wd.exe has been detected as adware by 10 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. This file is typically installed with the program PassShow by Revizer Technologies which is a potentially unwanted software program. This is part of the Revizer line of web browser extensions that inject 3rd-party advertisements in the user's web browser as well as setup a proxy server for the browser in order to track behaviors and display context based-ads from various partners (mostly adware).
MD5:
14c0e8676457d02bcdca3e7ab8cb48ff

SHA-1:
00d3225793e9cfb4b69822457615be4c95cdb15b

SHA-256:
94c7b06490b671aa937f49d9ead118a44adccbdb371f9579cc7ed65188c9791d

Scanner detections:
10 / 68

Status:
Adware

Analysis date:
4/26/2024 9:28:00 PM UTC  (today)

Scan engine
Detection
Engine version

avast!
Win32:Adware-BLC [PUP]
2014.9-141002

AVG
Generic5
2015.0.3334

Baidu Antivirus
Adware.Win32.AD150
4.0.3.14102

Comodo Security
Application.Win32.Adware.WDUnlocker.A
18095

ESET NOD32
Win32/AdWare.AD150 (variant)
8.9670

McAfee
Adware-AddLyrics!14C0E8676457
5600.6990

Panda Antivirus
Trj/Genetic.gen
14.10.02.06

Reason Heuristics
Adware.Revizer.Task.L
14.10.2.6

Trend Micro House Call
TROJ_GEN.R0C1H06CI14
7.2.275

VIPRE Antivirus
Adware.AddLyrics
28212

File size:
91.5 KB (93,696 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\passshow-soft\passshow_wd.exe

File PE Metadata
Compilation timestamp:
3/18/2014 7:37:17 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
1536:gkwj9uTaU7OgrOwRuBG1FZAcE6vlkwkSLZA0Xq9bqit:gkwJuTMszAcJvFLZA0XUbqi

Entry address:
0x6B0E

Entry point:
E8, F3, 57, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, B4, 12, 41, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 5F, 89, 45, FC, 5E, 85, C0, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 30, 11, 41, 00, C9, C2, 08, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 98, 71, 41, 00, 89, 0D, 94, 71, 41, 00, 89, 15, 90, 71, 41, 00, 89, 1D, 8C, 71, 41, 00, 89, 35, 88, 71, 41, 00, 89, 3D...
 
[+]

Entropy:
6.2077

Code size:
61.5 KB (62,976 bytes)

Scheduled Task
Task name:
PassShow_wd

Trigger:
Daily (Runs daily at 9:32 PM)


The file passshow_wd.exe has been discovered within the following program.

PassShow  by Revizer Technologies
PassShow is an adware program that integrates with the user's web browser (IE, Chrome and Firefox) and will hijack the normal home, search and new tab pages as well as redirections. In addition, it will display ads within the browser including banner, context and popup ads.
passshow.com
88% remove it
 
Powered by Should I Remove It?

Remove passshow_wd.exe - Powered by Reason Core Security