wpsvc.exe

Word Proser Client Service

Wordprosers LLC

This is part of the InfoAtoms browser extension which will display variopus forms of advertising in the web browser by injecting new ads such as banner, text-links and search results. The application wpsvc.exe by Wordprosers has been detected as adware by 8 anti-malware scanners. It runs as a separate (within the context of its own process) windows Service named “Word Proser 1.10.0.4 Client Service”.
Publisher:
Word Proser  (signed by Wordprosers LLC)

Product:
Word Proser Client Service

Version:
1.10.0.4

MD5:
6a90987d602e51d9d37828f6177eb17c

SHA-1:
d7f284f279739b0ebabc7d395e0f881a20cae8be

SHA-256:
d7eaff69b27379626bf40d888a74170a506e0969b256cd5b8dbe1167b0f20f8d

Scanner detections:
8 / 68

Status:
Adware

Analysis date:
1/24/2025 5:37:22 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Wordproser
2015.0.3269

ESET NOD32
Win32/AdWare.Vitruvian (variant)
8.10833

IKARUS anti.virus
PUA.Vitruvian
t3scan.1.8.5.0

Kaspersky
not-a-virus:AdWare.Win32.Vitruvian
14.0.0.2838

Malwarebytes
PUP.Optional.WordProser.A
v2014.12.06.10

Reason Heuristics
PUP.Service.Wordprosers.F
14.12.6.10

Vba32 AntiVirus
AdWare.Vitruvian
3.12.26.3

VIPRE Antivirus
InfoAtoms
35454

File size:
271.1 KB (277,584 bytes)

Product version:
1.10.0.4

Copyright:
Copyright (C) 2014

Original file name:
wpsvc.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\wordproser_1.10.0.4\service\wpsvc.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/30/2014 10:58:57 AM

Valid to:
6/30/2016 10:58:57 AM

Subject:
E=support@wordproser.com, CN=Wordprosers LLC, O=Wordprosers LLC, L=La Jolla, S=CA, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112185C82DF38C3E8058F8A898AF88A5B351

File PE Metadata
Compilation timestamp:
12/4/2014 5:22:03 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
11.0

CTPH (ssdeep):
6144:0Z4157+kGcAbVeuo7nABVQCTB+uBgxb1p:0Z4LC/cABeuo7ABVQCTCB1p

Entry address:
0x21158

Entry point:
E8, 69, 56, 00, 00, E9, 7B, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, 92, 00, 00, 00, 56, 53, 8B, D9, 8B, 74, 24, 14, F7, C6, 03, 00, 00, 00, 8B, 7C, 24, 10, 75, 0B, C1, E9, 02, 0F, 85, 85, 00, 00, 00, EB, 27, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 83, E9, 01, 74, 2B, 84, C0, 74, 2F, F7, C6, 03, 00, 00, 00, 75, E5, 8B, D9, C1, E9, 02, 75, 61, 83, E3, 03, 74, 13, 8A, 06, 83, C6, 01, 88, 07, 83, C7, 01, 84, C0, 74, 37, 83, EB, 01, 75, ED, 8B, 44...
 
[+]

Code size:
180.5 KB (184,832 bytes)

Service
Display name:
Word Proser 1.10.0.4 Client Service

Service name:
wpsvc_1.10.0.4

Description:
This service enables Word Proser 1.10.0.4 on HTTP websites

Type:
Win32OwnProcess


Remove wpsvc.exe - Powered by Reason Core Security