webprotect.exe

Montiera Technologies LTD

It is part of the Montiera web browser toolbar monetization platform which injects browser search and advertising within the user's web browser. The application webprotect.exe by Montiera Technologies has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered by a time event. This file is typically installed with the program Web Protect License by Montiera Technologies LTD which is a potentially unwanted software program.
Publisher:
Pay By Ads LTD  (signed by Montiera Technologies LTD)

Version:
1.3.0.0

MD5:
d6cce6da966ae5860f6fdd099ca5fd12

SHA-1:
4e77b9118094465d4a6cb11e6117a0b7b9724ab7

SHA-256:
0d67d2deab05fa185a5209622cb411021e0ab4899fb1ac97b6b1a40a57e39637

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 1:05:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Montiera.PayByAds (M)
16.3.28.21

File size:
536.9 KB (549,768 bytes)

Copyright:
All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\webprotect\webprotect\1.3.11.0\webprotect.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/22/2014 5:00:00 PM

Valid to:
7/23/2015 4:59:59 PM

Subject:
CN=Montiera Technologies LTD, O=Montiera Technologies LTD, STREET=Harbert Samuel 46, L=Tel Aviv, S=Gush Dan, PostalCode=6330303, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00CCD3CD85F8C32F5C3FF9264E1A57C07D

File PE Metadata
Compilation timestamp:
8/7/2014 2:02:18 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:tvdoSUGhvVZ166+VNqJla3cgJZCNfJJPbqMIdPNu39CCIrRoF+:HW/3d0NfJJTqMIdPNeCXFo

Entry address:
0x3FD42

Entry point:
E8, AE, 83, 00, 00, E9, 89, FE, FF, FF, B8, 3A, 8C, 44, 00, A3, 10, 7A, 46, 00, C7, 05, 14, 7A, 46, 00, 30, 83, 44, 00, C7, 05, 18, 7A, 46, 00, E4, 82, 44, 00, C7, 05, 1C, 7A, 46, 00, 1D, 83, 44, 00, C7, 05, 20, 7A, 46, 00, 86, 82, 44, 00, A3, 24, 7A, 46, 00, C7, 05, 28, 7A, 46, 00, B2, 8B, 44, 00, C7, 05, 2C, 7A, 46, 00, A2, 82, 44, 00, C7, 05, 30, 7A, 46, 00, 04, 82, 44, 00, C7, 05, 34, 7A, 46, 00, 90, 81, 44, 00, C3, 8B, FF, 55, 8B, EC, E8, 96, FF, FF, FF, 83, 7D, 08, 00, 74, 05, E8, BF, 8E, 00, 00, DB...
 
[+]

Entropy:
6.5641

Code size:
331.5 KB (339,456 bytes)

Scheduled Task
Task name:
Web Protect License

Trigger:
Time


The file webprotect.exe has been discovered within the following program.

Web Protect License  by Montiera Technologies LTD
WebProtect is a potentially unwanted software program ads a default home page and search engine provider to the user's web browser and protects the settings in order to collect search revenues.
73% remove it
 
Powered by Should I Remove It?

Remove webprotect.exe - Powered by Reason Core Security