internetenhancer.exe

0174V7

The application internetenhancer.exe has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This executable runs as a local area network (LAN) Internet proxy server listening on port 51303 and has the ability to intercept and modify all inbound and outbound Internet traffic on the local host. While running, it connects to the Internet address edge-star-shv-01-sin6.facebook.com on port 443.
Product:
0174V7

Version:
2.35.2.99

MD5:
a9b626a13db61fbb3ea5fd03efab0ce0

SHA-1:
44ae3038e4ffc44e4585308a779d30bf6e14c154

SHA-256:
d0a53b8b6e293efee5d5f6c1453207eeecda219bea9c74c6a68e684467b35f7a

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/10/2025 10:47:16 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Wajam.Meta (M)
15.9.1.18

File size:
260 KB (266,240 bytes)

Product version:
2.35.2.99

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\waintenhancer\waintenhancer internet enhancer\internetenhancer.exe

File PE Metadata
Compilation timestamp:
9/1/2015 11:06:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:8aX5WueeFwGDOPvR8CGMYngR18DCCFbqmiTBs+j61rPko9ZbId2moB3loLmhG4ch:Z5CGDA6tgRBmiT2+SPPnIdAWLBXHS2q

Entry address:
0x423FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
257.5 KB (263,680 bytes)

Local Proxy Server
Proxy for:
Internet Settings

Local host address:
http://127.0.0.1:51303/

Local host port:
51303

Default credentials:
No


The executing file has been seen to make the following network communications in live environments.

TCP (HTTP SSL):
Connects to a-0011.a-msedge.net  (204.79.197.213:443)

TCP (HTTP):
Connects to e1.ycpi.vip.deb.yahoo.com  (87.248.118.22:80)

TCP (HTTP):
Connects to a104-121-12-49.deploy.static.akamaitechnologies.com  (104.121.12.49:80)

TCP (HTTP):
Connects to rtr3.l7.search.vip.ir2.yahoo.com  (217.12.15.96:80)

TCP (HTTP):
Connects to r1.ycpi.vip.ir2.yahoo.net  (217.12.13.40:80)

TCP (HTTP):
Connects to ns04.hiwit.net  (194.150.236.156:80)

TCP (HTTP):
Connects to li491-84.members.linode.com  (50.116.29.84:80)

TCP (HTTP SSL):
Connects to bl3302-a.1drv.com  (134.170.107.152:443)

TCP (HTTP SSL):
Connects to a23-217-226-229.deploy.static.akamaitechnologies.com  (23.217.226.229:443)

TCP (HTTP):
Connects to a104-121-29-119.deploy.static.akamaitechnologies.com  (104.121.29.119:80)

TCP (HTTP):
Connects to a104-120-220-61.deploy.static.akamaitechnologies.com  (104.120.220.61:80)

TCP (HTTP):
Connects to a104-120-218-97.deploy.static.akamaitechnologies.com  (104.120.218.97:80)

TCP (HTTP):
Connects to us.redir.opera.com  (107.167.110.234:80)

TCP (HTTP):
Connects to map2.hwcdn.net  (205.185.216.10:80)

TCP (HTTP SSL):
Connects to lb03.us.ext.opera.com  (37.228.108.252:443)

TCP (HTTP SSL):
Connects to fna-fbcdn-shv-01-fdel1.fbcdn.net  (157.240.189.17:443)

TCP (HTTP SSL):
Connects to edge-star-shv-01-sin6.facebook.com  (157.240.7.20:443)

TCP (HTTP):
Connects to e2.ycpi.vip.fra.yahoo.com  (77.238.180.12:80)

TCP (HTTP):
Connects to a104-122-112-72.deploy.static.akamaitechnologies.com  (104.122.112.72:80)

TCP (HTTP):
Connects to a104-121-5-224.deploy.static.akamaitechnologies.com  (104.121.5.224:80)

Remove internetenhancer.exe - Powered by Reason Core Security