enformation

enformation

Known Adware

by Robokid Technologies

What is enformation?

enformation is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 59.41% of installations running this operating system. enformation's installer is typically 9.00 MB in size and installs around 129 files. The most common release is 1.34.7.1 with 90.10% of all installations currently using this version.

enformation is most popular in the United States with 77.70% of installations residing in this country.

enformation adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About enformation?

Enformation is an adware extension that operates within the user's web browser and runs as a background process. Typically, this program is bundled by a third-party download manager that includes potentially unwanted software offers in order to generate revenue through installations. Once activated, the software delivers advertisements in various formats including banners, text hyperlinks, inline text ads, and transitional ads. These ads are not affiliated with the websites on which they appear. Many of the advertisements are considered malvertising, promoting products that could potentially harm the user's PC, such as additional software downloads, price comparison, and search ads. Furthermore, the software communicates with a remote server to report the user's browsing habits, URLs, and domains visited in order to update its advertisements. The program's uninstaller may not function properly, leaving behind remnants of the software and causing ads to persist even after removal. According to the program's End User License Agreement (EULA), advertisements may be targeted based on the user's browser queries, information processed by the software, or other information provided or collected from the user's use of the software.

Multiple virus scanners have detected malware in enformation.

5d421e7c-6d53-4810-b1aa-5a495f532e4f-4.exe (MD5: ca557dacb3b0e5ac03d6d6a618a7f548) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.958889
Avira AntiVir Adware/CrossRider.A.12581
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Adware.Generic.958889
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.958889 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.958889
G Data Adware.Generic.958889
Malwarebytes PUP.Optional.Enformation.A
MicroWorld-eScan Adware.Generic.958889
NANO AntiVirus Riskware.Win32.AdLoad.dbsohi
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.ca5
TrendMicro-HouseCall Suspicious_GEN.F47V0627
VIPRE Antivirus Crossrider (fs)
McAfee RDN/Generic PUP.x!cjm
McAfee-GW-Edition RDN/Generic PUP.x!cjm
Symantec Trojan.Gen.2
F-Prot W32/A-eb9ef301!Eldorado
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
AhnLab-V3 PUP/Win32.CrossRider
AVG Generic.332
AVware Crossrider (fs)
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Antiy-AVL Trojan/Win32.TSGeneric
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Agnitum Outpost PUA.Toolbar.CroRi!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
Clam AntiVirus Win.Adware.Agent-7572
Bkav FE W32.CrossRiderN.Adware
5d421e7c-6d53-4810-b1aa-5a495f532e4f-11.exe (MD5: cf268becf96fdbe22ceb68ac224cb2ba) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Generic.957659
Avira AntiVir Adware/CrossRider.A.12538
avast! Win32:Adware-gen [Adw]
Baidu-International Adware.Win32.CrossRider.BAD
Bitdefender Adware.Generic.957659
Clam AntiVirus Win.Adware.Agent-7424
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Adware.Generic.957659 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Secure Adware.Generic.957659
G Data Adware.Generic.957659
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Malwarebytes PUP.Optional.Enformation.A
MicroWorld-eScan Adware.Generic.957659
NANO AntiVirus Riskware.Win32.AdLoad.dbsnxs
Qihoo-360 Win32/Virus.Adware.8e9
VIPRE Antivirus Crossrider (fs)
IKARUS anti.virus AdWare.Adload
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
McAfee Artemis!CC01AC5B4D43
McAfee-GW-Edition Artemis!CC01AC5B4D43
Panda Antivirus Trj/Genetic.gen
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R047H05GG14
AVG Generic.332
Sophos Generic PUA JI
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Antiy-AVL Trojan/Win32.TSGeneric
Agnitum Outpost PUA.Toolbar.CroRi!
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
Bkav FE W32.CrossRiderN.Adware
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-5.exe (MD5: 7f82c79ab14bdd5cfadc995229549066) has been flagged by 25 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAH
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.Enformation.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
VIPRE Antivirus Crossrider (fs)
F-Prot W32/A-eb9ef301!Eldorado
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos AppRider
Fortinet FortiGate Riskware/Toolbar_CrossRider
McAfee Artemis!AD2825A4B825
McAfee-GW-Edition Artemis!AD2825A4B825
NANO AntiVirus Riskware.Win32.AdLoad.dbegav
TrendMicro-HouseCall Suspicious_GEN.F47V0704
AVware Crossrider (fs)
Symantec Trojan.ADH.2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.s
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Clam AntiVirus Win.Adware.Agent-7620
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-4.exe (MD5: 434ee7d1074be5858726a36cd6e4a09e) has been flagged by 35 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAK
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.Enformation.A
McAfee Artemis!434EE7D1074B
McAfee-GW-Edition Artemis!434EE7D1074B
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA PD
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0720
VIPRE Antivirus Crossrider (fs)
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Qihoo-360 HEUR/Malware.QVM10.Gen
Lavasoft Ad-Aware Trojan.Generic.11530953
Bitdefender Trojan.Generic.11530953
Emsisoft Anti-Malware Trojan.Generic.11530953 (B)
F-Secure Trojan.Generic.11530953
G Data Trojan.Generic.11530953
MicroWorld-eScan Trojan.Generic.11530953
NANO AntiVirus Riskware.Win32.AdLoad.dbxccs
Agnitum Outpost PUA.Toolbar.CroRi!
AVware Crossrider (fs)
Kaspersky not-a-virus:WebToolbar.Win32.CroRi.ng
AhnLab-V3 PUP/Win32.CrossRider
Rising Antivirus PE:Malware.Obscure!1.9C59
F-Prot W32/A-eb9ef301!Eldorado
Clam AntiVirus Win.Adware.Agent-7572
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
5d2b6f92-62f9-4a0a-9b75-331f9b67203c-2.exe (MD5: 8b5a366979811314296d15fcf0a1f499) has been flagged by 25 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAJ
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.Enformation.A
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
McAfee Artemis!AF8642BA688E
McAfee-GW-Edition Artemis!AF8642BA688E
NANO AntiVirus Riskware.Win32.AdLoad.dcccfd
Symantec Trojan.Gen.2
TrendMicro-HouseCall Suspicious_GEN.F47V0710
Fortinet FortiGate Riskware/Toolbar_CrossRider
Qihoo-360 HEUR/Malware.QVM10.Gen
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.s
Bkav FE W32.CrossRiderN.Adware
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Clam AntiVirus Win.Adware.Agent-7620

Software Behaviors

Scheduled tasks:
  • enformation-nova.exe is scheduled as a task named 'temp_2d57afe2-44cd-4e8d-963a-fc053b6f8943-7'.
  • 8932d600-01e1-4ab8-a0db-7bea877aff85-2.exe is scheduled as a task named 'temp_8932d600-01e1-4ab8-a0db-7bea877aff85-2'.

Startup Entries

Startup tasks:
  • enformation-codedownloader.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-6.
  • enformation-nova.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-7.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-5.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-5_user.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-4.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-4.
  • 8be706a5-2cc0-4b47-b433-b529554c2dfa-11.exe is automatically launched at startup through a scheduled task named 3f44ebf3-78a8-4b36-97d7-a7a1dff682bc-11.
  • 3cf44ffe-54e6-4725-b4cc-a5df288ef21b-5.exe is automatically launched at startup through a scheduled task named 15695293-8d38-4afb-b0f6-f43a44b54fb5-5_user.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\enformation
Uninstaller:
C:\Program Files\enformation\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

enformation Executable Details

Primary executable:
utils.exe
Name:
enformation
Path:
C:\Program Files\enformation\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by enformation
File Type Filename MD5
EXE
bcf15bd9e645caf733a8e1d5120cc66d
EXE
24895123c1084500e09865ac53e76449
EXE
e1409519b589a67b848416c38cf3721c
EXE
4aaf29ca27569f5536cb334cf825ea53
EXE
4482c473fce05493325624f22b2a7fce
EXE
e007d387104ccd86e65989cc5b720102
EXE
54cffdaee33a95b7816c9d47ac66f3c1
EXE
4ec6bcb161f2da5c753692773dbf6967
EXE
6e26d3a3140591fd1a425ea7e17ded7d
EXE
1dee58c89409e0e9a63d42c177a6ba37