enformation

enformation

Known Adware

by Robokid Technologies

What is enformation?

enformation is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 59.41% of installations running this operating system. enformation's installer is typically 9.00 MB in size and installs around 129 files. The most common release is 1.34.7.1 with 90.10% of all installations currently using this version.

enformation is most popular in the United States with 77.70% of installations residing in this country.

enformation adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About enformation?

Enformation is an adware extension that operates within the user's web browser and runs as a background process. Typically, this program is bundled by a third-party download manager that includes potentially unwanted software offers in order to generate revenue through installations. Once activated, the software delivers advertisements in various formats including banners, text hyperlinks, inline text ads, and transitional ads. These ads are not affiliated with the websites on which they appear. Many of the advertisements are considered malvertising, promoting products that could potentially harm the user's PC, such as additional software downloads, price comparison, and search ads. Furthermore, the software communicates with a remote server to report the user's browsing habits, URLs, and domains visited in order to update its advertisements. The program's uninstaller may not function properly, leaving behind remnants of the software and causing ads to persist even after removal. According to the program's End User License Agreement (EULA), advertisements may be targeted based on the user's browser queries, information processed by the software, or other information provided or collected from the user's use of the software.

Multiple virus scanners have detected malware in enformation.

5d421e7c-6d53-4810-b1aa-5a495f532e4f-4.exe (MD5: ca557dacb3b0e5ac03d6d6a618a7f548) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.958889
Avira AntiVir Adware/CrossRider.A.12581
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Adware.Generic.958889
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.958889 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.958889
G Data Adware.Generic.958889
Malwarebytes PUP.Optional.Enformation.A
MicroWorld-eScan Adware.Generic.958889
NANO AntiVirus Riskware.Win32.AdLoad.dbsohi
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.ca5
TrendMicro-HouseCall Suspicious_GEN.F47V0627
VIPRE Antivirus Crossrider (fs)
McAfee RDN/Generic PUP.x!cjm
McAfee-GW-Edition RDN/Generic PUP.x!cjm
Symantec Trojan.Gen.2
F-Prot W32/A-eb9ef301!Eldorado
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.332
AVware Crossrider (fs)
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Antiy-AVL Trojan/Win32.TSGeneric
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Agnitum Outpost PUA.Toolbar.CroRi!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
Clam AntiVirus Win.Adware.Agent-7572
Bkav FE W32.CrossRiderN.Adware
5d421e7c-6d53-4810-b1aa-5a495f532e4f-11.exe (MD5: cf268becf96fdbe22ceb68ac224cb2ba) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.957659
Avira AntiVir Adware/CrossRider.A.12538
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Adware.Generic.957659
Clam AntiVirus Win.Adware.Agent-7424
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.957659 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.957659
G Data Adware.Generic.957659
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Malwarebytes PUP.Optional.Enformation.A
MicroWorld-eScan Adware.Generic.957659
NANO AntiVirus Riskware.Win32.AdLoad.dbsnxs
Qihoo-360 Win32/Virus.Adware.8e9
VIPRE Antivirus Crossrider (fs)
IKARUS anti.virus AdWare.Adload
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
McAfee Artemis!CC01AC5B4D43
McAfee-GW-Edition Artemis!CC01AC5B4D43
Panda Antivirus Trj/Genetic.gen
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R047H05GG14
AVG Generic.332
Sophos Generic PUA JI
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Agnitum Outpost PUA.Toolbar.CroRi!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
Bkav FE W32.CrossRiderN.Adware
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-5.exe (MD5: 7f82c79ab14bdd5cfadc995229549066) has been flagged by 25 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAH
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.Enformation.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
F-Prot W32/A-eb9ef301!Eldorado
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
Fortinet FortiGate Riskware/Toolbar_CrossRider
McAfee Artemis!AD2825A4B825
McAfee-GW-Edition Artemis!AD2825A4B825
NANO AntiVirus Riskware.Win32.AdLoad.dbegav
TrendMicro-HouseCall Suspicious_GEN.F47V0704
AVware Crossrider (fs)
Symantec Trojan.ADH.2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.s
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Clam AntiVirus Win.Adware.Agent-7620
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-4.exe (MD5: 434ee7d1074be5858726a36cd6e4a09e) has been flagged by 35 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAK
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.Enformation.A
McAfee Artemis!434EE7D1074B
McAfee-GW-Edition Artemis!434EE7D1074B
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA PD
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0720
VIPRE Antivirus Crossrider (fs)
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Qihoo-360 HEUR/Malware.QVM10.Gen
Lavasoft Ad-Aware Trojan.Generic.11530953
Bitdefender Trojan.Generic.11530953
Emsisoft Anti-Malware Trojan.Generic.11530953 (B)
F-Secure Trojan.Generic.11530953
G Data Trojan.Generic.11530953
MicroWorld-eScan Trojan.Generic.11530953
NANO AntiVirus Riskware.Win32.AdLoad.dbxccs
Agnitum Outpost PUA.Toolbar.CroRi!
AVware Crossrider (fs)
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
Clam AntiVirus Win.Adware.Agent-7572
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-2.exe (MD5: 8b5a366979811314296d15fcf0a1f499) has been flagged by 25 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.Enformation.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!AF8642BA688E
McAfee-GW-Edition Artemis!AF8642BA688E
NANO AntiVirus Riskware.Win32.AdLoad.dcccfd
Symantec Trojan.Gen.2
TrendMicro-HouseCall Suspicious_GEN.F47V0710
Fortinet FortiGate Riskware/Toolbar_CrossRider
Qihoo-360 HEUR/Malware.QVM10.Gen
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.s
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Clam AntiVirus Win.Adware.Agent-7620

Software Behaviors

Scheduled tasks:
  • enformation-nova.exe is scheduled as a task named 'temp_2d57afe2-44cd-4e8d-963a-fc053b6f8943-7'.
  • 8932d600-01e1-4ab8-a0db-7bea877aff85-2.exe is scheduled as a task named 'temp_8932d600-01e1-4ab8-a0db-7bea877aff85-2'.

Startup Entries

Startup tasks:
  • enformation-codedownloader.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-6.
  • enformation-nova.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-7.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-5.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-5_user.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-4.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-4.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-11.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-11.
  • 3cf44ffe-54e6-4725-b4cc-a5df288ef21b-5.exe is automatically launched at startup through a scheduled task named 15695293-8d38-4afb-b0f6-f43a44b54fb5-5_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\enformation
Uninstaller:
C:\Program Files\enformation\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

enformation Executable Details

Primary executable:
utils.exe
Name:
enformation
Path:
C:\Program Files\enformation\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by enformation
File Type Filename MD5
EXE
6d35e5f8cdb9fec0e79c169fa877a74d
EXE
d1dcc9211db1b61986270e2f34b88b65
EXE
32226046c2333c46a66e3d788d938b90
EXE
cdf861aac0f96d98f158f02cb9b9aebe
EXE
28d79ae3978b5d9cd1e03d3f98cb3807
EXE
3eb38ec683f14d2c1f232155eb657019
EXE
abadb01a8aeaf4adbbeafb8bc7c97228
EXE
8db5b05c6ffe0ed40ace2f3d8b16f9db
EXE
aa0354b486b5a654ffa5f5ce2e758a7c
EXE
00cfe0e1c6b089aaf9dc8a50d82ab592