safeguardapp.exe

Alerts LLC

Part of an adware web browser extension that delivers advertisements such as coupons, price-comparisons, display media, affiliate links, banners, popups/popunders and other links. The application safeguardapp.exe by Alerts has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘SafeGuard’. This file is typically installed with the program SafeGuard by Alerts LLC which is a potentially unwanted software program.
Publisher:
Alerts LLC  (signed and verified)

Version:
1.0.2.45

MD5:
88d860eb44ef8222df9539aab68fbbcd

SHA-1:
ff7fb3d87b3b7dd5ec65e924853c6367df1a68f4

SHA-256:
bf482fe9141b621be61c5dd71c0baf65e3263a193c96dc65e21efb2953927cd7

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/23/2024 7:50:10 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Weather.Alerts (M)
16.2.19.4

File size:
1.5 MB (1,537,552 bytes)

Product version:
1.0.2.45

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\safeguard\safeguardapp.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/4/2014 5:00:00 PM

Valid to:
6/5/2015 4:59:59 PM

Subject:
CN=Alerts LLC, O=Alerts LLC, STREET="101 Colorado St #2309", L=Austin, S=TX, PostalCode=78701, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00A4FE74573C3AAF1867F4DF866A77B161

File PE Metadata
Compilation timestamp:
4/1/2015 11:30:25 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:/r3favvSEa9uCw0EDoAomHqKwGgyihANVXFR/34SWYKF1Rl4cB8EQ4wylIfjTDzP:7f+vXbr0XK3g8NVVbsl73DlIgxJ9U

Entry address:
0x4CB03

Entry point:
E8, F5, C7, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A1, 00, C2, 53, 00, 33, C5, 89, 45, FC, 83, 7D, 08, FF, 57, 74, 09, FF, 75, 08, E8, 40, A5, 00, 00, 59, 83, A5, E0, FC, FF, FF, 00, 6A, 4C, 8D, 85, E4, FC, FF, FF, 6A, 00, 50, E8, 19, C2, FF, FF, 8D, 85, E0, FC, FF, FF, 89, 85, D8, FC, FF, FF, 8D, 85, 30, FD, FF, FF, 83, C4, 0C, 89, 85, DC, FC, FF, FF, 89, 85, E0, FD, FF, FF, 89, 8D, DC, FD, FF, FF, 89, 95, D8, FD, FF, FF, 89, 9D, D4, FD, FF, FF, 89, B5, D0, FD, FF, FF, 89, BD, CC...
 
[+]

Entropy:
5.9456

Code size:
953 KB (975,872 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
SafeGuard

Command:
"C:\Program Files\safeguard\safeguardapp.exe"


The file safeguardapp.exe has been discovered within the following program.

SafeGuard  by Alerts LLC
83% remove it
 
Powered by Should I Remove It?

Remove safeguardapp.exe - Powered by Reason Core Security