wizpop_uninstall.exe

corenet

The application wizpop_uninstall.exe by corenet has been detected as a potentially unwanted program by 24 anti-malware scanners. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
corenet  (signed and verified)

MD5:
60b284b881dee851704ff1c1fe8a0fc7

SHA-1:
571a1ec7ece686138e7e6062dc20a5fb4caba141

SHA-256:
0f70ed3549e4d920d7aa322937809c0b72e642c8de7f7484e945d2372d4dccaa

Scanner detections:
24 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 12:11:52 AM UTC  (today)

Scan engine
Detection
Engine version

AhnLab V3 Security
PUP/Win32.WizPop
2015.05.02

avast!
Win32:Malware-gen
2014.9-151113

AVG
Skodna.Generic
2016.0.2927

Baidu Antivirus
Adware.Win32.Kraddare
4.0.3.151113

Bkav FE
W32.WizpopLnrA.Adware
1.3.0.6379

Comodo Security
UnclassifiedMalware
21971

ESET NOD32
Win32/Adware.Kraddare.BL
9.11564

Fortinet FortiGate
W32/Adware_fam.NB
11/13/2015

G Data
Win32.Trojan.Agent.IOOK37
15.11.25

IKARUS anti.virus
Skodna.SuspectCRC
t3scan.1.8.9.0

K7 AntiVirus
Adware
13.203.15783

McAfee
Artemis!60B284B881DE
5600.6583

Norman
Agent.VCYE
11.20151113

Panda Antivirus
Trj/CI.A
15.11.13.09

Qihoo 360 Security
Win32/Trojan.Adware.992
1.0.0.1015

Quick Heal
Adware.Wizpop.AZ4
11.15.14.00

Rising Antivirus
PE:Trojan.Win32.Generic.129D6CB7!312306871
23.00.65.151111

Sophos
Generic PUA FH
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Wiser
9510

Trend Micro House Call
ADW_KRADDARE
7.2.317

Trend Micro
ADW_KRADDARE
10.465.13

Vba32 AntiVirus
Adware.Kraddare
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
39874

Zillya! Antivirus
Adware.WizPop.Win32.13
2.0.0.2164

File size:
67.1 KB (68,704 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\wizpop\wizpop_uninstall.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
10/4/2011 6:00:00 PM

Valid to:
10/4/2013 5:59:59 PM

Subject:
CN=corenet, O=corenet, L="Uijeongbu-si ", S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
61A656767E655D1859C3E6CC8632D65A

File PE Metadata
Compilation timestamp:
7/28/2011 2:41:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:/5OM1VuxJ7QCD9isUqyG1sBkIxAKN2clBKqNfONizBE9:/Buv7VD9b0xB2KNexNiK

Entry address:
0x288A0

Entry point:
60, BE, 00, A0, 41, 00, 8D, BE, 00, 70, FE, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, EF, 75, 09, 8B, 1E, 83, EE, FC, 11, DB, 73, E4, 31, C9, 83, E8, 03, 72, 0D, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 74, 89, C5, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, 75, 20, 41, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB...
 
[+]

Entropy:
7.8357

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
60 KB (61,440 bytes)

Remove wizpop_uninstall.exe - Powered by Reason Core Security