winpro.exe

WinKey

nbiz Ltd.

The application winpro.exe by nbiz has been detected as adware by 29 anti-malware scanners.
Publisher:
NBIZ Corp.  (signed by nbiz Ltd.)

Product:
WinKey

Description:
WinPro

Version:
1, 0, 0, 1

MD5:
c34750d0857809e2cd2a1dfdaeaaade0

SHA-1:
e16bf9e2d0d257857e06e5e72ab044511819beaa

Scanner detections:
29 / 68

Status:
Adware

Analysis date:
4/19/2024 8:06:12 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Adware.Kraddare
7.1.1

AhnLab V3 Security
PUP/Win32.WinPro
15.04.22

Avira AntiVirus
Adware/SideTab.1.7
7.11.151.204

avast!
Win32:Sidetab-A [Adw]
2014.9-150422

AVG
Skodna.Generic
2016.0.3131

Baidu Antivirus
Adware.Win32.Kraddare
4.0.3.15422

Bitdefender
Gen:Variant.Adware.Sidetab.1
1.0.20.560

Clam AntiVirus
Win.Adware.Sidetab-64
0.98/213

Comodo Security
UnclassifiedMalware
18349

Dr.Web
Trojan.DownLoader6.42250
9.0.1.0112

Emsisoft Anti-Malware
Gen:Variant.Adware.Sidetab
8.15.04.22.05

ESET NOD32
Win32/Adware.Kraddare.EJ
9.9857

Fortinet FortiGate
Riskware/Kraddare
4/22/2015

F-Secure
Gen:Variant.Adware.Sidetab.1
11.2015-22-04_4

G Data
Gen:Variant.Adware.Sidetab
15.4.24

IKARUS anti.virus
Win32.SuspectCrc
t3scan.1.6.1.0

Malwarebytes
Adware.KorAd
v2015.04.22.05

McAfee
Artemis!C34750D08578
5600.6787

MicroWorld eScan
Gen:Variant.Adware.Sidetab.1
16.0.0.336

NANO AntiVirus
Trojan.Win32.Kraddare.ygaro
0.28.0.59921

Panda Antivirus
Generic Malware
15.04.22.05

Qihoo 360 Security
Win32/Trojan.Adware.37e
1.0.0.1015

Quick Heal
Adware.SideOn (Not a Virus)
4.15.14.00

Reason Heuristics
Threat.nbiz
15.4.22.13

Sophos
nbiz
4.98

Trend Micro House Call
ADW_KRADDARE
7.2.112

Trend Micro
ADW_KRADDARE
10.465.22

VIPRE Antivirus
Trojan.Win32.Generic
29680

Zillya! Antivirus
Adware.Kraddare.Win32.964
2.0.0.1803

File size:
82.1 KB (84,072 bytes)

Product version:
1, 0, 0, 1

Copyright:
(c) NBIZ. All rights reserved.

Original file name:
WinKey.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\winpro\winpro.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
1/9/2012 9:00:00 AM

Valid to:
3/10/2013 8:59:59 AM

Subject:
CN=nbiz Ltd., OU=Software Development Department, O=nbiz Ltd., L=Gangnam-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
670AA12980346CE791E731546CA9D8AC

File PE Metadata
Compilation timestamp:
3/29/2012 2:25:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:VmfV/XprL2iDF/niIQygUv9nI1rMnnPSil:VmfV/Xp1p/niInnIinPSU

Entry address:
0xA47C

Entry point:
55, 8B, EC, 6A, FF, 68, A8, CC, 40, 00, 68, 70, A4, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 2C, C3, 40, 00, 59, 83, 0D, F8, 1A, 41, 00, FF, 83, 0D, FC, 1A, 41, 00, FF, FF, 15, 30, C3, 40, 00, 8B, 0D, EC, 1A, 41, 00, 89, 08, FF, 15, 34, C3, 40, 00, 8B, 0D, E8, 1A, 41, 00, 89, 08, A1, 38, C3, 40, 00, 8B, 00, A3, F4, 1A, 41, 00, E8, 16, 01, 00, 00, 39, 1D, D0, 19, 41, 00, 75, 0C, 68, FE, A5, 40, 00, FF, 15, 3C, C3...
 
[+]

Entropy:
5.5995

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
44 KB (45,056 bytes)

Remove winpro.exe - Powered by Reason Core Security