windowpurchase.exe

DOTPITCH.INC

The application windowpurchase.exe by DOTPITCH.INC has been detected as adware by 9 anti-malware scanners.
Publisher:
DOTPITCH.INC  (signed and verified)

MD5:
37df573ecc10dde5e757a359bc565851

SHA-1:
fc9f5fb0ec1584f387fff78c3a161a1877582c1b

Scanner detections:
9 / 68

Status:
Adware

Analysis date:
4/19/2024 8:33:47 PM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
Win-PUP/Helper.WindowPurchase.74360
15.03.07

Avira AntiVirus
Adware/Kraddare.IP
7.11.151.204

Bkav FE
W32.Clodc20.Trojan
1.3.0.4959

Comodo Security
ApplicUnwnt
18347

McAfee
RDN/Generic.tfr!ds
5600.6833

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1015

Reason Heuristics
PUP.DOTPITCHINC
15.3.7.22

Trend Micro House Call
PAK_Generic.005
7.2.66

Trend Micro
PAK_Generic.005
10.465.07

File size:
72.6 KB (74,360 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Application data\windowpurchase\windowpurchase.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
3/12/2013 9:00:00 AM

Valid to:
4/12/2014 8:59:59 AM

Subject:
CN=DOTPITCH.INC, OU=Marketing, O=DOTPITCH.INC, L=Seocho-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
0AA240F3D167B5B6AF5A20903B60B16F

File PE Metadata
Compilation timestamp:
7/23/2013 6:50:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:JzCO192fFSacnqTT6Y/OwABsuJDWbDtWNnV3jUuTObv/F4ps7+Nl:Jzf14fFXy6Tj/pIdJDgkYRCF

Entry address:
0x2B230

Entry point:
60, BE, 00, B0, 41, 00, 8D, BE, 00, 60, FE, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75...
 
[+]

Entropy:
7.8621

Packer / compiler:
UPX 2.90LZMA

Code size:
68 KB (69,632 bytes)

Remove windowpurchase.exe - Powered by Reason Core Security