130ef59e-911e-469c-8c89-171bc6b920d9-1-6.exe

Word Proser Driver x64

Wordprosers LLC

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application 130ef59e-911e-469c-8c89-171bc6b920d9-1-6.exe by Wordprosers has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Word Proser  (signed by Wordprosers LLC)

Product:
Word Proser Driver x64

Version:
1.10.0.6

MD5:
e289e14a27556983938e68d96e31f3f1

SHA-1:
8b699256ec696a4e04197eb3e700511953c5be6f

SHA-256:
bdd5b4a93a108cda2565a44a7a4217a6f03102bacf6ce0a7cebf02880ccdbcbb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:24:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InfoAtoms (M)
16.7.19.22

File size:
1.3 MB (1,413,080 bytes)

Product version:
1.10.0.6

Copyright:
Copyright (C) 2015

Original file name:
wpnfd.sys

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cinema video pro 2.1v09.02\130ef59e-911e-469c-8c89-171bc6b920d9-1-6.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/30/2014 3:58:57 PM

Valid to:
6/30/2016 3:58:57 PM

Subject:
E=support@wordproser.com, CN=Wordprosers LLC, O=Wordprosers LLC, L=La Jolla, S=CA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112185C82DF38C3E8058F8A898AF88A5B351

File PE Metadata
Compilation timestamp:
8/22/2012 12:34:56 AM

OS version:
6.0

OS bitness:
Win64

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
24576:5L1LgHOiGxSdVRudb0RX3owL1PvXlTZOTSpS/e7+6Pg+LTGJw:nLjCRG0RX1OTSpS/e7BY+LTGJw

Entry address:
0x10008

Entry point:
48, 8B, 05, F1, D0, FF, FF, 49, B9, 32, A2, DF, 2D, 99, 2B, 00, 00, 48, 85, C0, 74, 05, 49, 3B, C1, 75, 2F, 4C, 8D, 05, D6, D0, FF, FF, 48, B8, 20, 03, 00, 00, 80, F7, FF, FF, 48, 8B, 00, 49, 33, C0, 49, B8, FF, FF, FF, FF, FF, FF, 00, 00, 49, 23, C0, 49, 0F, 44, C1, 48, 89, 05, AE, D0, FF, FF, 48, F7, D0, 48, 89, 05, AC, D0, FF, FF, E9, DB, B0, FF, FF, CC, CC, CC, B0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, B4, 04, 01, 00, 10, C0, 00, 00, A0, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, D6, 04, 01, 00...
 
[+]

Code size:
44 KB (45,056 bytes)

Remove 130ef59e-911e-469c-8c89-171bc6b920d9-1-6.exe - Powered by Reason Core Security