What is WinZipper?

WinZipper is software application developed by Taiwan Shui Mu Chih Ching Technology Limited.. It is most commonly found on computers running Windows 7 with nearly 64.00% of installations running this operating system. WinZipper's installer is typically 6.00 MB in size and installs around 28 files. The most common release is 1.4.8 with 37.04% of all installations currently using this version.

WinZipper is most popular in Germany with 12.02% of installations residing in this country.

WinZipper adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About WinZipper?

The free and trial versions include a variety of additional toolbars and web browser extensions, including the AVG Toolbar, which may modify the browser's search and home page settings.

Multiple virus scanners have detected malware in WinZipper.

winzipper.exe (MD5: a3bd563073759a2d257950b229592e6d) has been flagged by 20 scanners:
Scanner Software Result
Symantec WS.Reputation
TrendMicro-HouseCall TROJ_GEN.F47V0613
Lavasoft Ad-Aware Application.Elex.A
Agnitum Outpost Riskware.Agent!
AVG AdPlugin.HS
AVware Trojan.Win32.Generic!BT
Bitdefender Application.Elex.A
Bkav FE W32.HfsAdware.CA66
Dr.Web Adware.Mutabaha.218
ESET-NOD32 a variant of Win32/ELEX.Y potentially unwanted
Fortinet FortiGate Riskware/Elex
F-Secure Application.Elex.A
G Data Application.Elex.A
McAfee Artemis!D4E0FDF50630
MicroWorld-eScan Application.Elex.A
NANO AntiVirus Riskware.Win32.D365.csnrev
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.ELEX.Win32.5
Baidu-International Adware.Win32.Elex.sig
Panda Antivirus PUP/XTab
eshellctx64.dll (MD5: b83d91e59bfb428b18cb16baf60afb5d) has been flagged by 5 scanners:
Scanner Software Result
Bkav FE W64.HfsAdware.CA66
Dr.Web Adware.Mutabaha.218
Panda Antivirus PUP/XTab
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0326
eshellctx.dll (MD5: 3796b7050f05c509a8e69ca9a4f612fb) has been flagged by 7 scanners:
Scanner Software Result
Baidu-International Adware.Win32.Elex.sig
Dr.Web Adware.Mutabaha.50
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V1229
Zillya Adware.ELEX.Win32.4
Bkav FE W64.HfsAdware.CA66
Panda Antivirus PUP/XTab
winzipersvc.exe (MD5: d4e0fdf5063039965c675cca933f9130) has been flagged by 20 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Elex.A
Agnitum Outpost Riskware.Agent!
AVG AdPlugin.HS
AVware Trojan.Win32.Generic!BT
Bitdefender Application.Elex.A
Bkav FE W32.HfsAdware.CA66
Dr.Web Adware.Mutabaha.218
ESET-NOD32 a variant of Win32/ELEX.Y potentially unwanted
Fortinet FortiGate Riskware/Elex
F-Secure Application.Elex.A
G Data Application.Elex.A
McAfee Artemis!D4E0FDF50630
MicroWorld-eScan Application.Elex.A
NANO AntiVirus Riskware.Win32.D365.csnrev
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.ELEX.Win32.5
Baidu-International Adware.Win32.Elex.sig
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V1229
Panda Antivirus PUP/XTab

Software Behaviors

Services:
  • winzipersvc.exe runs as a service named 'WinZiper service' (winzipersvc) "WinZipper service".
  • winzipersvc(49).exe runs as a service named 'WinZiper service' (winzipersvc) "WinZipper service".
Scheduled tasks:
  • eUninstall.exe is scheduled as a task with the class '{6FA703F0-6E80-44E7-A6DE-004C74227CCF}' (runs on registration).
  • WinZipper.exe is scheduled as a task with the class '{C2EBFEAC-F0B8-4F56-941C-B0676E183A21}' (runs on registration).

Software Details

URL:
https://www.winzipper.com
Support:
Installation path:
C:\Program Files\winzipper
Uninstaller:
C:\Program Files\WinZipper\eUninstall.exe
Size:
6.00 MB
Language:
English

WinZipper Executable Details

Primary executable:
winzipper.exe
Name:
WinZipper
Path:
C:\Program Files\winzipper\winzipper.exe
MD5:
a3bd563073759a2d257950b229592e6d
SHA-1:
SHA-256:
Files installed by WinZipper
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
a570666f0655a1e03f9f837099c92630
DLL
f9bb3bc7790be8e49c25fdcc0d18339d
DLL
5cad5792bb209694db6e36baa2ca83ea
DLL
d1270adf50a2134620404f477d9f29fd
DLL
2cbb35ffc48e3343fbb85a12ef912716
DLL
a07b3606ceb6b1ae96feceeb6b2511b5
DLL
8767e12c067cfa3107aa4d1d1985d2c2
DLL
fc11c9f0420c05a29b5fb33898d05197
EXE
3b11e687e4ef565b84e76eae92fa6b81