wpnfd_1_10_0_4.sys

Word Proser Driver x86

Wordprosers LLC

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The file wpnfd_1_10_0_4.sys by Wordprosers has been detected as adware by 7 anti-malware scanners. It runs as a Windows kernel mode device driver named “wpnfd_1_10_0_4”.
Publisher:
Word Proser  (signed by Wordprosers LLC)

Product:
Word Proser Driver x86

Version:
1.10.0.4

MD5:
4b9c4a2acc61a0a29dd84e5d7355ad62

SHA-1:
8e98ac240ad3b5239186e54e8a16cfeaf4086f78

SHA-256:
e859019173969664c577f25535abbdeed10ce0ee2d1724a4867739964e2c9635

Scanner detections:
7 / 68

Status:
Adware

Analysis date:
11/5/2024 4:42:49 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Popad
7.1.1

AVG
Wordproser
2015.0.3266

Dr.Web
Adware.Popad.10
9.0.1.0342

IKARUS anti.virus
AdWare.Vitruvian
t3scan.1.8.5.0

Kaspersky
not-a-virus:AdWare.Win64.Vitruvian
14.0.0.2826

Malwarebytes
PUP.Optional.WordProser.A
v2014.12.08.05

Reason Heuristics
PUP.Wordprosers.R
14.12.8.17

File size:
51.5 KB (52,736 bytes)

Product version:
1.10.0.4

Copyright:
Copyright (C) 2014

Original file name:
wpnfd.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\Windows\System32\drivers\wpnfd_1_10_0_4.sys

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/30/2014 4:58:57 PM

Valid to:
6/30/2016 4:58:57 PM

Subject:
E=support@wordproser.com, CN=Wordprosers LLC, O=Wordprosers LLC, L=La Jolla, S=CA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112185C82DF38C3E8058F8A898AF88A5B351

File PE Metadata
Compilation timestamp:
8/22/2012 1:34:53 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
8.0

CTPH (ssdeep):
768:VH47urAd7AVbTXO2vZd1VjXjurCIDaCCepa+ez8oc3fjgkC5EtI23irT:x47ue7ITew1JXCrdDqe43cPkn+tWn

Entry address:
0xA085

Entry point:
8B, FF, 55, 8B, EC, A1, 00, 8C, 01, 00, 85, C0, B9, 4E, E6, 40, BB, 74, 04, 3B, C1, 75, 1E, 8B, 15, 08, 8B, 01, 00, B8, 00, 8C, 01, 00, C1, E8, 08, 33, 02, A3, 00, 8C, 01, 00, 75, 07, 8B, C1, A3, 00, 8C, 01, 00, F7, D0, A3, 04, 8C, 01, 00, 5D, E9, 51, E7, FF, FF, CC, 2C, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A8, A4, 00, 00, 94, 8A, 00, 00, 18, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, A4, 00, 00, 80, 8A, 00, 00, 24, A1, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, FA, A4, 00, 00, 8C, 8A, 00, 00, 00...
 
[+]

Code size:
34.8 KB (35,584 bytes)

Driver
Display name:
wpnfd_1_10_0_4

Type:
Kernel device driver (KernelDriver)

Group:
PNP_TDI


Remove wpnfd_1_10_0_4.sys - Powered by Reason Core Security