el.exe

a

Itzhak Shternberg

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application el.exe by Itzhak Shternberg has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
storage principles memory  (signed by Itzhak Shternberg)

Product:
a

Version:
5.5.0.0

MD5:
e55c7879f9166d34a369512793109e8b

SHA-1:
e0327f2f7b05e6c5ea6f06ebceea65816d88e29b

SHA-256:
66b4c0a5c921ba6c41be2bfa12bb0ab46fa01da2c38daeca06b243f6d7cd7918

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
1/12/2025 5:17:36 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
17.3.16.9

File size:
782.7 KB (801,512 bytes)

Product version:
5.5.0.0

Copyright:
Copyright (c) 2014

Original file name:
example

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\users\{user}\downloads\el.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/17/2013 6:00:00 PM

Valid to:
7/18/2014 5:59:59 PM

Subject:
CN=Itzhak Shternberg, O=Itzhak Shternberg, STREET=Belkind 2, L=Tel Aviv, S=Tel Aviv, PostalCode=62154, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
54990006BE4A0F29ECCD7EE2F93DC0FC

File PE Metadata
Compilation timestamp:
7/12/2014 7:02:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x15D3E

Entry point:
E8, 6B, 75, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, C8, BD, 42, 00, E8, 3C, 27, 00, 00, E8, BC, 0E, 00, 00, 0F, B7, F0, 6A, 02, E8, FE, 74, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, A0, 3A, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
7.6906

Code size:
139 KB (142,336 bytes)

Remove el.exe - Powered by Reason Core Security