windowadvertisement.exe

windowadvertisement

enliple Ltd.

The application windowadvertisement.exe by enliple has been detected as a potentially unwanted program by 2 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler named WindowAdvertisement triggered to execute each time a user logs in. This file is typically installed with the program WindowAdvertisement by enliple Ltd which is a potentially unwanted software program.
Publisher:
enliple Ltd.  (signed and verified)

Product:
windowadvertisement

Version:
10.00

MD5:
fed0da44ce138d9fef79494c48fd4e1b

SHA-1:
fd09c067e664300356a248cde635f0f3ff334d19

SHA-256:
cf1d53d3e8d1815421787d36eb64c96014edf78b62b16df778c0390ca39afc7c

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 6:55:03 AM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
BACKDOOR.Trojan
9.0.1.0141

Reason Heuristics
PUP.enliple.T
14.5.21.22

File size:
5.8 MB (6,106,984 bytes)

Product version:
10.00

Original file name:
windowadvertisement.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\windowadvertisement\windowadvertisement.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/26/2013 9:00:00 AM

Valid to:
6/27/2015 8:59:59 AM

Subject:
CN=enliple Ltd., OU=Internet Dept, O=enliple Ltd., L=Guro-gu, S=SEOUL, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
178A151BFE91D2CFD345640D3EE64736

File PE Metadata
Compilation timestamp:
5/16/2014 4:18:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:w0CR9B8BjGNg6Sf+00CR9B8BjGNg6Sf+b0CR9B8BjGNg6Sf+t0CR9B8BjGNg6Sfp:w0CR9B8BjGNg6Sf+00CR9B8BjGNg6Sfd

Entry address:
0x793C

Entry point:
68, FC, 49, 43, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 48, 00, 00, 00, 00, 00, 00, 00, C9, 4B, 6C, 3B, DA, 34, 64, 40, 8D, F1, 8A, 91, 7F, B9, 03, D2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 20, 20, 20, 42, 61, 63, 77, 69, 6E, 64, 6F, 77, 61, 64, 76, 65, 72, 74, 69, 73, 65, 6D, 65, 6E, 74, 00, 30, 46, 46, 43, 00, 00, 00, 00, FF, CC, 31, 00, 99, 5E, 7D, 6B, 09, D5, 44, FA, 42, 8E, E6, 1C, F7, 8D, 79, E9, 8D, EC, 30, AA, 08, 10, 48, 03, 46, 88, 53, CA, 61, 10, F2, 2A, C5, 3A, 4F, AD...
 
[+]

Entropy:
6.4121

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
3.4 MB (3,563,520 bytes)

Scheduled Task
Task name:
WindowAdvertisement

Trigger:
Logon (Runs on logon)


The file windowadvertisement.exe has been discovered within the following program.

WindowAdvertisement  by enliple Ltd
The software runs unwanted processes or programs on the user's computer and does not display adequate disclosures about its behavior.
75% remove it
 
Powered by Should I Remove It?

Remove windowadvertisement.exe - Powered by Reason Core Security