LicenseInfo.exe

Utilities

Data Protection Solutions

This is part of an adware program designed to inject advertising in the web browser (banners, text-links) as well as modify the normal behavior of the browser. Part of the Injekt brand of unwanted programs. The application LicenseInfo.exe by Data Protection Solutions has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Data Protection Solutions  (signed and verified)

Product:
Utilities

Version:
1.0.0.5

MD5:
728aa6626b4272075485e8e181ac4427

SHA-1:
fd5b13faac671a212b76551e5b358f9ba0fb639e

SHA-256:
8ad6aad8a0a2c1a65d9adb45b9d583bb5af736a5071793f3ca731f7c7ae5febb

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
12/25/2024 11:27:47 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt.DataProt (M)
16.5.24.19

File size:
93.4 KB (95,632 bytes)

Product version:
1.0.0.5

Copyright:
Copyright © 2009 - 2010

Trademarks:
EzBackup

Original file name:
LicenseInfo.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\dps\ezbackup 5.0\licenseinfo.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
7/13/2011 8:00:00 AM

Valid to:
6/2/2012 7:59:59 AM

Subject:
CN=Data Protection Solutions, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Data Protection Solutions, L=Hollywood, S=Florida, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
44EB7C831EAB6F108628776BD16D247B

File PE Metadata
Compilation timestamp:
3/15/2012 10:54:04 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
1536:3s7y9jtH+FgUK4+QWsCcRnG8534PRbbWTGHi:c70tH+FgUK4+QWsCaG8534BWTwi

Entry address:
0x167FE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.9608

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
82.5 KB (84,480 bytes)

Remove LicenseInfo.exe - Powered by Reason Core Security