enformation

enformation

Known Adware

by Robokid Technologies

What is enformation?

enformation is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 59.41% of installations running this operating system. enformation's installer is typically 9.00 MB in size and installs around 129 files. The most common release is 1.34.7.1 with 90.10% of all installations currently using this version.

enformation is most popular in the United States with 77.70% of installations residing in this country.

enformation adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About enformation?

Enformation is an adware extension that operates within the user's web browser and runs as a background process. Typically, this program is bundled by a third-party download manager that includes potentially unwanted software offers in order to generate revenue through installations. Once activated, the software delivers advertisements in various formats including banners, text hyperlinks, inline text ads, and transitional ads. These ads are not affiliated with the websites on which they appear. Many of the advertisements are considered malvertising, promoting products that could potentially harm the user's PC, such as additional software downloads, price comparison, and search ads. Furthermore, the software communicates with a remote server to report the user's browsing habits, URLs, and domains visited in order to update its advertisements. The program's uninstaller may not function properly, leaving behind remnants of the software and causing ads to persist even after removal. According to the program's End User License Agreement (EULA), advertisements may be targeted based on the user's browser queries, information processed by the software, or other information provided or collected from the user's use of the software.

Multiple virus scanners have detected malware in enformation.

5d421e7c-6d53-4810-b1aa-5a495f532e4f-4.exe (MD5: ca557dacb3b0e5ac03d6d6a618a7f548) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.958889
Avira AntiVir Adware/CrossRider.A.12581
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Adware.Generic.958889
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.958889 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.958889
G Data Adware.Generic.958889
Malwarebytes PUP.Optional.Enformation.A
MicroWorld-eScan Adware.Generic.958889
NANO AntiVirus Riskware.Win32.AdLoad.dbsohi
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.ca5
TrendMicro-HouseCall Suspicious_GEN.F47V0627
VIPRE Antivirus Crossrider (fs)
McAfee RDN/Generic PUP.x!cjm
McAfee-GW-Edition RDN/Generic PUP.x!cjm
Symantec Trojan.Gen.2
F-Prot W32/A-eb9ef301!Eldorado
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.332
AVware Crossrider (fs)
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Antiy-AVL Trojan/Win32.TSGeneric
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Agnitum Outpost PUA.Toolbar.CroRi!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
Clam AntiVirus Win.Adware.Agent-7572
Bkav FE W32.CrossRiderN.Adware
5d421e7c-6d53-4810-b1aa-5a495f532e4f-11.exe (MD5: cf268becf96fdbe22ceb68ac224cb2ba) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.957659
Avira AntiVir Adware/CrossRider.A.12538
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Adware.Generic.957659
Clam AntiVirus Win.Adware.Agent-7424
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.957659 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.957659
G Data Adware.Generic.957659
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Malwarebytes PUP.Optional.Enformation.A
MicroWorld-eScan Adware.Generic.957659
NANO AntiVirus Riskware.Win32.AdLoad.dbsnxs
Qihoo-360 Win32/Virus.Adware.8e9
VIPRE Antivirus Crossrider (fs)
IKARUS anti.virus AdWare.Adload
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
McAfee Artemis!CC01AC5B4D43
McAfee-GW-Edition Artemis!CC01AC5B4D43
Panda Antivirus Trj/Genetic.gen
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R047H05GG14
AVG Generic.332
Sophos Generic PUA JI
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Agnitum Outpost PUA.Toolbar.CroRi!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
Bkav FE W32.CrossRiderN.Adware
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-5.exe (MD5: 7f82c79ab14bdd5cfadc995229549066) has been flagged by 25 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAH
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.Enformation.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
F-Prot W32/A-eb9ef301!Eldorado
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
Fortinet FortiGate Riskware/Toolbar_CrossRider
McAfee Artemis!AD2825A4B825
McAfee-GW-Edition Artemis!AD2825A4B825
NANO AntiVirus Riskware.Win32.AdLoad.dbegav
TrendMicro-HouseCall Suspicious_GEN.F47V0704
AVware Crossrider (fs)
Symantec Trojan.ADH.2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.s
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Clam AntiVirus Win.Adware.Agent-7620
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-4.exe (MD5: 434ee7d1074be5858726a36cd6e4a09e) has been flagged by 35 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAK
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.Enformation.A
McAfee Artemis!434EE7D1074B
McAfee-GW-Edition Artemis!434EE7D1074B
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA PD
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0720
VIPRE Antivirus Crossrider (fs)
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Qihoo-360 HEUR/Malware.QVM10.Gen
Lavasoft Ad-Aware Trojan.Generic.11530953
Bitdefender Trojan.Generic.11530953
Emsisoft Anti-Malware Trojan.Generic.11530953 (B)
F-Secure Trojan.Generic.11530953
G Data Trojan.Generic.11530953
MicroWorld-eScan Trojan.Generic.11530953
NANO AntiVirus Riskware.Win32.AdLoad.dbxccs
Agnitum Outpost PUA.Toolbar.CroRi!
AVware Crossrider (fs)
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
Clam AntiVirus Win.Adware.Agent-7572
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-2.exe (MD5: 8b5a366979811314296d15fcf0a1f499) has been flagged by 25 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.Enformation.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!AF8642BA688E
McAfee-GW-Edition Artemis!AF8642BA688E
NANO AntiVirus Riskware.Win32.AdLoad.dcccfd
Symantec Trojan.Gen.2
TrendMicro-HouseCall Suspicious_GEN.F47V0710
Fortinet FortiGate Riskware/Toolbar_CrossRider
Qihoo-360 HEUR/Malware.QVM10.Gen
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.s
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Clam AntiVirus Win.Adware.Agent-7620

Software Behaviors

Scheduled tasks:
  • enformation-nova.exe is scheduled as a task named 'temp_2d57afe2-44cd-4e8d-963a-fc053b6f8943-7'.
  • 8932d600-01e1-4ab8-a0db-7bea877aff85-2.exe is scheduled as a task named 'temp_8932d600-01e1-4ab8-a0db-7bea877aff85-2'.

Startup Entries

Startup tasks:
  • enformation-codedownloader.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-6.
  • enformation-nova.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-7.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-5.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-5_user.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-4.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-4.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-11.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-11.
  • 3cf44ffe-54e6-4725-b4cc-a5df288ef21b-5.exe is automatically launched at startup through a scheduled task named 15695293-8d38-4afb-b0f6-f43a44b54fb5-5_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\enformation
Uninstaller:
C:\Program Files\enformation\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

enformation Executable Details

Primary executable:
utils.exe
Name:
enformation
Path:
C:\Program Files\enformation\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by enformation
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
a0bdc8051a740904d9e5f24d697f6875
EXE
2ce27c90c4463ae9a6a3e64eb5bf4e9c
EXE
ca557dacb3b0e5ac03d6d6a618a7f548
EXE
26017b551d49a5ce143379cb94f84bbb
EXE
cf268becf96fdbe22ceb68ac224cb2ba
EXE
7f82c79ab14bdd5cfadc995229549066
EXE
434ee7d1074be5858726a36cd6e4a09e
EXE
8b5a366979811314296d15fcf0a1f499
EXE
85ceb14c4c6375928182ab63b8fdbe52