waclkoo.exe

Finance Alert

Valid Applications

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application waclkoo.exe, “FinanceAlert Service” by Valid Applications has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Valid Applications  (signed and verified)

Product:
Finance Alert

Description:
FinanceAlert Service

Version:
1.0.0.0

MD5:
e537d88026f9a1bfd5bad2f90ff95c9c

SHA-1:
43fe624a7f64dda2a03d789db81f68d46ebc8658

SHA-256:
9bce1c0c5600d08fe6713eb951a8aefd833716a0c4b8eba473653059888308af

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
6/23/2025 7:19:11 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt
17.2.4.7

File size:
2.6 MB (2,732,288 bytes)

Product version:
1.0.0.0

Copyright:
Copyright © Valid Applications 2015

Original file name:
FinanceAlertService.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\lnxogl\waclkoo.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/15/2014 2:00:00 AM

Valid to:
10/16/2015 1:59:59 AM

Subject:
CN=Valid Applications, O=Valid Applications, L=St. James, S=St. James, C=BB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
085BF49B5A62F0A47208B968B1916037

File PE Metadata
Compilation timestamp:
6/22/2015 5:17:45 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

Entry address:
0x29AD1E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
2.6 MB (2,723,328 bytes)

Remove waclkoo.exe - Powered by Reason Core Security