wifi protector extension-bg.exe

Wifi Protector Extension

Safe Download Limited

The application wifi protector extension-bg.exe, “Wifi Protector Extension exe” by Safe Download Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Wifi Protector Extension by Speedchecker Limited which is a potentially unwanted software program. While running, it connects to the Internet address hwcdn.net on port 80 using the HTTP protocol.
Publisher:
Speedchecker  (signed by Safe Download Limited)

Product:
Wifi Protector Extension

Description:
Wifi Protector Extension exe

Version:
1.1.150.30

MD5:
c528cab2bdfb58d2a2bfec7a1016f1e1

SHA-1:
d36179b9f55364b5a00182d443b71a0c980f6fce

SHA-256:
577b87ed9b05f30ef3a2b5f9757381d48560b23cd55c3e73e2bb08195ea8793a

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 12:19:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SpeedChecker.SafeDownload (M)
16.2.6.2

File size:
772.7 KB (791,280 bytes)

Product version:
1.1.150.30

Copyright:
Copyright 2011

Original file name:
Wifi Protector Extension.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wifi protector extension\wifi protector extension-bg.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/1/2012 7:30:00 PM

Valid to:
8/26/2014 7:30:00 AM

Subject:
CN=Safe Download Limited, O=Safe Download Limited, L=Douglas, S=Douglas, C=IM

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0DD2FC97B3C6597CABD97B29D9383440

File PE Metadata
Compilation timestamp:
8/2/2012 6:51:45 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:Dr/yaeE5iN+AG5UQveZq9pN2kw5ZaiRGejitM1OT9CtH654rf:Dr/yaeGw+5CQ5pjktGe7I9CtH65G

Entry address:
0x6CEB3

Entry point:
E8, 1A, A7, 00, 00, E9, 89, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46, 1C, 57, 50, E8, 8D, D8, FF, FF, 33, C0, 0F, B7, C8, 8B, C1, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, C1, E1, 10, 0B, C1, 8D, 7E, 10, AB, AB, AB, B9, A8, CE, 4B, 00, 83, C4, 0C, 8D, 46, 1C, 2B, CE, BF, 01, 01, 00, 00, 8A, 14, 01...
 
[+]

Code size:
643.5 KB (658,944 bytes)

The file wifi protector extension-bg.exe has been discovered within the following program.

Wifi Protector Extension  by Speedchecker Limited
Wifi Protector Extension is a web browser toolbar and extension that modifies the browsers search and home pages as well as delivers contextual based advertising. This toolbar currently supports Internet Explorer, Firefox and Chrome.
67% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to hwcdn.net  (69.16.175.10:80)

Remove wifi protector extension-bg.exe - Powered by Reason Core Security