Home Malware Programs Potentially Unwanted Programs (PUPs) Wordproser

Wordproser

Posted: October 20, 2014

Threat Metric

Ranking: 10,433
Threat Level: 2/10
Infected PCs: 76,013
First Seen: October 20, 2014
Last Seen: February 21, 2025
OS(es) Affected: Windows


Wordproser is an unwanted program that computer researchers have ousted as an adware application that displays random advertisements. The Wordproser ads may be banners or pop-ups where they prove to be intrusive by interrupting your surfing of the internet. Usually the Wordproser ads will attempt to offer random products and services and ways to add functions to your web browser applications. Most computer users will find the Wordproser services as unwanted add-ons or become annoyed at the several Wordproser pop-ups loaded that if clicked, may cause redirects to other sites that have questionable content. Removal of Wordproser may be performed automatically by use of an antispyware application.

Aliases

Wordproser.7D0 [AVG]Adware/Vitruvian [Fortinet]Trojan/Win32.SGeneric [Antiy-AVL]Artemis [McAfee-GW-Edition]Adware.Plugin.274 [DrWeb]ApplicUnwnt [Comodo]Generic PUA EK [Sophos]not-a-virus:AdWare.Win32.Vitruvian.a [Kaspersky]Trojan.Gen.2 [Symantec]Adware ( 004a9fae1 ) [K7AntiVirus]Artemis!0BF1004D2D52 [McAfee]AdWare.Win64.r6 (Not a Virus) [CAT-QuickHeal]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\WordProser_1.10.0.6\Service\wpsvc.exe File name: wpsvc.exe
Size: 277.58 KB (277584 bytes)
MD5: 9774b8a352319d8e1969eaff18709fc3
Detection count: 8,190
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\WordProser_1.10.0.6\Service\wpsvc.exe
Group: Malware file
Last Updated: January 23, 2024
C:\AdwCleaner\Quarantine\C\Program Files (x86)\wordproser_1.10.0.5\Service\wpsvc.exe.vir File name: wpsvc.exe.vir
Size: 277.58 KB (277584 bytes)
MD5: b3b547f875928fadff3beaf5d3dc1fc5
Detection count: 7,408
Mime Type: unknown/vir
Path: C:\AdwCleaner\Quarantine\C\Program Files (x86)\wordproser_1.10.0.5\Service\wpsvc.exe.vir
Group: Malware file
Last Updated: January 31, 2023
C:\System Volume Information\_restore{4A6875BD-F03A-4E04-BAA5-224D81EDCBF8}\RP199\A0159664.sys File name: A0159664.sys
Size: 52.73 KB (52736 bytes)
MD5: 4b9c4a2acc61a0a29dd84e5d7355ad62
Detection count: 6,642
File type: System file
Mime Type: unknown/sys
Path: C:\System Volume Information\_restore{4A6875BD-F03A-4E04-BAA5-224D81EDCBF8}\RP199\A0159664.sys
Group: Malware file
Last Updated: August 30, 2022
c:\windows\system32\drivers\wpnfd_1_10_0_1.sys File name: wpnfd_1_10_0_1.sys
Size: 52.73 KB (52736 bytes)
MD5: f8971170ff3b508e47ecd2367558892e
Detection count: 5,579
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\wpnfd_1_10_0_1.sys
Group: Malware file
Last Updated: March 27, 2022
%PROGRAMFILES%\WordProser\IE\WordProserClientIE.dll File name: WordProserClientIE.dll
Size: 254.03 KB (254032 bytes)
MD5: 7b1ec8a997bf53b2113f8c549923da38
Detection count: 65
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\WordProser\IE
Group: Malware file
Last Updated: May 25, 2017
system32\drivers\wpnfd_1_10_0_6.sys File name: wpnfd_1_10_0_6.sys
Size: 58.24 KB (58240 bytes)
MD5: d60d1d327c27e7ead4e18e4f5881c523
Detection count: 63
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: April 9, 2016
system32\drivers\wpnfd_1_10_0_9.sys File name: wpnfd_1_10_0_9.sys
Size: 58.24 KB (58240 bytes)
MD5: 17aa25f4ddd583f4510bf05470483dfc
Detection count: 33
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: January 30, 2020
%WINDIR%\System32\drivers\wpnfd_1_10_0_4.sys File name: wpnfd_1_10_0_4.sys
Size: 58.24 KB (58240 bytes)
MD5: 7c47f94089fb8f4f3f37d5b30e684b54
Detection count: 26
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: April 9, 2016
%WINDIR%\System32\drivers\wpnfd.sys File name: wpnfd.sys
Size: 58.24 KB (58240 bytes)
MD5: 23b70f71debec2a59e1c2c1d1c2016a1
Detection count: 14
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: April 9, 2016
%WINDIR%\System32\drivers\wpnfd_1_10_0_2.sys File name: wpnfd_1_10_0_2.sys
Size: 58.24 KB (58240 bytes)
MD5: b1a87ece0a320d2d71c3bbf7247b8bad
Detection count: 6
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: April 9, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{03A19B15-6866-4B99-97A7-57F359C40931}{3EBB5099-9732-48AE-B032-58B702D86EEC}{F6F484C9-29B9-43EC-A924-DCBAAA86B31D}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F6F484C9-29B9-43EC-A924-DCBAAA86B31D}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F6F484C9-29B9-43EC-A924-DCBAAA86B31D}SOFTWARE\Mozilla\Firefox\Extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{F6F484C9-29B9-43EC-A924-DCBAAA86B31D}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F6F484C9-29B9-43EC-A924-DCBAAA86B31D}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{6e7f6f9f-8ce6-4611-add2-05f0f7049ee6}SYSTEM\ControlSet001\Enum\Root\LEGACY_WPNFD_1_10_0_1SYSTEM\ControlSet001\Enum\Root\LEGACY_WPNFD_1_10_0_2SYSTEM\ControlSet001\services\wpnfd_1_10_0_1SYSTEM\ControlSet001\services\wpnfd_1_10_0_2SYSTEM\ControlSet001\services\wpnfd_1_10_0_5SYSTEM\ControlSet001\services\wpsvc_1.10.0.2SYSTEM\ControlSet001\services\wpsvc_1.10.0.5SYSTEM\ControlSet002\Enum\Root\LEGACY_WPNFD_1_10_0_1SYSTEM\ControlSet002\Enum\Root\LEGACY_WPNFD_1_10_0_2SYSTEM\ControlSet002\services\wpnfd_1_10_0_1SYSTEM\ControlSet002\services\wpnfd_1_10_0_2SYSTEM\ControlSet002\services\wpnfd_1_10_0_5SYSTEM\ControlSet002\services\wpsvc_1.10.0.2SYSTEM\ControlSet002\services\wpsvc_1.10.0.5SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WPNFD_1_10_0_1SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WPNFD_1_10_0_2SYSTEM\CurrentControlSet\services\wpnfd_1_10_0_1SYSTEM\CurrentControlSet\services\wpnfd_1_10_0_2SYSTEM\CurrentControlSet\services\wpsvc_1.10.0.2

Additional Information

The following directories were created:
%PROGRAMFILES%\Mozilla Firefox\extensions\{d9a96531-b093-4d07-9e4c-9704a365c441}%PROGRAMFILES%\WordProser_1.10.0.6%PROGRAMFILES(x86)%\Mozilla Firefox\extensions\{d9a96531-b093-4d07-9e4c-9704a365c441}%PROGRAMFILES(x86)%\WordProser_1.10.0.6
Loading...