windowadvertisement.exe

windowadvertisement

enliple Ltd.

The application windowadvertisement.exe by enliple has been detected as a potentially unwanted program by 16 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named WindowAdvertisement triggered to execute each time a user logs in. This file is typically installed with the program WindowAdvertisement by enliple Ltd which is a potentially unwanted software program.
Publisher:
enliple Ltd.  (signed and verified)

Product:
windowadvertisement

Version:
8.03

MD5:
c1ce54bd47cce45fee16fcd427f30a2c

SHA-1:
938b1183871d6b31cb95acbe848ef7ca5cb54902

SHA-256:
a26b608f8cb9c2364b60d75334ea35c6ff4c6a0a494e7698e97d0b65294d181f

Scanner detections:
16 / 68

Status:
Potentially unwanted

Analysis date:
5/9/2024 4:58:55 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Graftor.119101
887

Agnitum Outpost
Riskware.AdWare
7.1.1

Bitdefender
Gen:Variant.Graftor.119101
1.0.20.1215

Comodo Security
ApplicUnwnt
17737

Dr.Web
BACKDOOR.Trojan
9.0.1.0243

Emsisoft Anti-Malware
Gen:Variant.Graftor.119101
8.14.08.31.03

ESET NOD32
Win32/AdWare.Kraddare.JC (variant)
8.9387

Fortinet FortiGate
Riskware/Kraddare
8/31/2014

F-Secure
Gen:Variant.Graftor.119101
11.2014-31-08_1

G Data
Gen:Variant.Graftor.119101
14.8.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.2.2.29

MicroWorld eScan
Gen:Variant.Graftor.119101
15.0.0.729

Reason Heuristics
PUP.enliple.T
14.8.31.15

File size:
3.5 MB (3,706,728 bytes)

Product version:
8.03

Original file name:
windowadvertisement.exe

File type:
Executable application (Win32 EXE)

Language:
Korean

Common path:
C:\Program Files\windowadvertisement\windowadvertisement.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/26/2013 2:00:00 AM

Valid to:
6/27/2015 1:59:59 AM

Subject:
CN=enliple Ltd., OU=Internet Dept, O=enliple Ltd., L=Guro-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
178A151BFE91D2CFD345640D3EE64736

File PE Metadata
Compilation timestamp:
1/17/2014 1:09:03 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:k0CR9B8BjGNg6Sf+R0CR9B8BjGNg6Sf+P0CR9B8BjGNg6Sf+n0CR9B8BjGNg6SfI:k0CR9B8BjGNg6Sf+R0CR9B8BjGNg6Sfq

Entry address:
0x71B8

Entry point:
68, A4, 40, 43, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, D7, B6, BC, A3, 07, C1, 5A, 48, 83, CB, 7F, E6, 2E, B6, 3E, 9A, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 77, 69, 6E, 64, 6F, 77, 61, 64, 76, 65, 72, 74, 69, 73, 65, 6D, 65, 6E, 74, 00, 43, 3A, 5C, 57, 00, 00, 00, 00, FF, CC, 31, 00, 91, 65, A3, AA, EC, FF, E4, EE, 48, 97, 40, D2, 90, BA, 41, 47, C7, AF, 80, 2E, 3E, F9, 1E, 13, 43, AB, 17, CC, CC, B2, 7A, 10, 94, 3A, 4F, AD...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
3.4 MB (3,518,464 bytes)

Scheduled Task
Task name:
WindowAdvertisement

Trigger:
Logon (Runs on logon)


The file windowadvertisement.exe has been discovered within the following program.

WindowAdvertisement  by enliple Ltd
The software runs unwanted processes or programs on the user's computer and does not display adequate disclosures about its behavior.
75% remove it
 
Powered by Should I Remove It?

Remove windowadvertisement.exe - Powered by Reason Core Security