Gridinsoft Logo
File Icon

Setup (2).exe PUP WebCompanion Analysis

Technical Analysis

File Name Setup (2).exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.155.174
Database Version 2024-01-17 05:02:21 UTC

PUP.Win32.WebCompanion.ns

Malware family: WebCompanion

WebCompanion is antivirus software developed by Adaware for malware protection and privacy security. It is classified as potentially unwanted due to distribution methods that some users consider intrusive.
N/A
Detection Rate
545,160
File Size (bytes)
2024-01-17
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
4329e751d1eaf1c42ecf288b5729b1f6
SHA1
9d232f56149dc6d6665f4803ea5cd307453a164f
SHA256
4a8ad32fea2a3fc643955a06422316c15635a0f24c1b43ee91d1bc208fc9fda5
SHA512
0538321643e64476cdf48ee433744e62abd2c7f159028b9733346f5c88a504a85df1bad770f191da3bff23ce6e839b6f1e831ebac1f7b82403d5b81154c046fc
ImpHash
e00de6e48b9b06aceb12a81e7bf494c9

PE Analysis

Basic Information

Icon
Hash: 5d22a7ff7121dddf8a76e69fbfa77d4f
Fuzzy: 12c3f1debd31ced5359a163aa35b6563
dHash: 00118ac8c4686900
Image Base 0x00400000
Entry Point 0x004148d4
Compilation Time 2011-04-18 18:54:06
Checksum 0x0009021c (Actual: 0x0008ac44)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 4 libraries
OLEAUT32, USER32, SHELL32, KERNEL32
Exports 0 functions
Resources 14 Resources
Sections 5 Sections

Digital Signatures

Entrust Root Certification Authority - G2 Entrust, Inc. (US)
Entrust Root Certification Authority - G2 Entrust, Inc. (US)
Entrust Code Signing Root Certification Authority - CSBR1 Entrust, Inc. (US)
Entrust Extended Validation Code Signing CA - EVCS2 Lavasoft Software Canada Inc. (CA)

Version Information

FileVersion 12.901.2.991
ProductVersion 12.901.2.991
CompanyName Lavasoft
FileDescription Web Companion Installer
InternalName Installer.exe
LegalCopyright c Lavasoft Limited. All Rights Reserved.
OriginalFilename Installer.exe
ProductName Web Companion Installer
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 104,384 bytes 104,448 bytes 6.61 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 206B62D600BEB166F8BF863AD5301F8C
.rdata 0x0001b000 17,552 bytes 17,920 bytes 4.38 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B0314F39355CAB7D4674A0928D3B15F2
.data 0x00020000 23,144 bytes 12,800 bytes 1.38 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8D44C03D32E0C923339CDA9FAE15827A
.sxdata 0x00026000 4 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_LNK_INFO|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 35925CFDC1176BD9FFC634A58B40EC17
.rsrc 0x00027000 29,132 bytes 29,184 bytes 4.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 80D1267689DD064ED497A799C053CA89
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 14 (28,276 bytes)
Resource Type Count Total Size Percentage
RT_ICON 7 25,291 bytes
89.4%
RT_DIALOG 1 184 bytes
0.7%
RT_STRING 2 200 bytes
0.7%
RT_GROUP_ICON 2 110 bytes
0.4%
RT_VERSION 1 828 bytes
2.9%
RT_MANIFEST 1 1,663 bytes
5.9%

Certificate Chain Analysis

Certificate #1
Subject Entrust Root Certification Authority - G2
Entrust, Inc.
US
Issuer Entrust Root Certification Authority - G2
Serial Number 1246989352
Certificate #2
Subject Entrust Code Signing Root Certification Authority - CSBR1
Entrust, Inc.
US
Issuer Entrust Root Certification Authority - G2
Serial Number 104016719443392582891195013311543612543
Certificate #3
Subject Entrust Extended Validation Code Signing CA - EVCS2
Entrust, Inc.
US
Issuer Entrust Code Signing Root Certification Authority - CSBR1
Serial Number 71361457201517752660581604742734624043
Certificate #4
Subject Lavasoft Software Canada Inc.
Lavasoft Software Canada Inc.
CA
Issuer Entrust Extended Validation Code Signing CA - EVCS2
Serial Number 155432911550719099163106291658133271269
Certificate Verification Status

OK

PUP.Win32.WebCompanion.ns Removal

Gridinsoft has the capability to identify and eliminate PUP.Win32.WebCompanion.ns without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware