What is WinZipper?

WinZipper is software application developed by Taiwan Shui Mu Chih Ching Technology Limited.. It is most commonly found on computers running Windows 7 with nearly 64.00% of installations running this operating system. WinZipper's installer is typically 6.00 MB in size and installs around 28 files. The most common release is 1.4.8 with 37.04% of all installations currently using this version.

WinZipper is most popular in Germany with 12.02% of installations residing in this country.

WinZipper adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About WinZipper?

The free and trial versions include a variety of additional toolbars and web browser extensions, including the AVG Toolbar, which may modify the browser's search and home page settings.

Multiple virus scanners have detected malware in WinZipper.

winzipper.exe (MD5: a3bd563073759a2d257950b229592e6d) has been flagged by 20 scanners:
Scanner Software Result
Symantec WS.Reputation
TrendMicro-HouseCall TROJ_GEN.F47V0613
Lavasoft Ad-Aware Application.Elex.A
Agnitum Outpost Riskware.Agent!
AVG AdPlugin.HS
AVware Trojan.Win32.Generic!BT
Bitdefender Application.Elex.A
Bkav FE W32.HfsAdware.CA66
Dr.Web Adware.Mutabaha.218
ESET-NOD32 a variant of Win32/ELEX.Y potentially unwanted
Fortinet FortiGate Riskware/Elex
F-Secure Application.Elex.A
G Data Application.Elex.A
McAfee Artemis!D4E0FDF50630
MicroWorld-eScan Application.Elex.A
NANO AntiVirus Riskware.Win32.D365.csnrev
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.ELEX.Win32.5
Baidu-International Adware.Win32.Elex.sig
Panda Antivirus PUP/XTab
eshellctx64.dll (MD5: b83d91e59bfb428b18cb16baf60afb5d) has been flagged by 5 scanners:
Scanner Software Result
Bkav FE W64.HfsAdware.CA66
Dr.Web Adware.Mutabaha.218
Panda Antivirus PUP/XTab
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0326
eshellctx.dll (MD5: 3796b7050f05c509a8e69ca9a4f612fb) has been flagged by 7 scanners:
Scanner Software Result
Baidu-International Adware.Win32.Elex.sig
Dr.Web Adware.Mutabaha.50
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V1229
Zillya Adware.ELEX.Win32.4
Bkav FE W64.HfsAdware.CA66
Panda Antivirus PUP/XTab
winzipersvc.exe (MD5: d4e0fdf5063039965c675cca933f9130) has been flagged by 20 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Elex.A
Agnitum Outpost Riskware.Agent!
AVG AdPlugin.HS
AVware Trojan.Win32.Generic!BT
Bitdefender Application.Elex.A
Bkav FE W32.HfsAdware.CA66
Dr.Web Adware.Mutabaha.218
ESET-NOD32 a variant of Win32/ELEX.Y potentially unwanted
Fortinet FortiGate Riskware/Elex
F-Secure Application.Elex.A
G Data Application.Elex.A
McAfee Artemis!D4E0FDF50630
MicroWorld-eScan Application.Elex.A
NANO AntiVirus Riskware.Win32.D365.csnrev
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.ELEX.Win32.5
Baidu-International Adware.Win32.Elex.sig
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V1229
Panda Antivirus PUP/XTab

Software Behaviors

Services:
  • winzipersvc.exe runs as a service named 'WinZiper service' (winzipersvc) "WinZipper service".
  • winzipersvc(49).exe runs as a service named 'WinZiper service' (winzipersvc) "WinZipper service".
Scheduled tasks:
  • eUninstall.exe is scheduled as a task with the class '{6FA703F0-6E80-44E7-A6DE-004C74227CCF}' (runs on registration).
  • WinZipper.exe is scheduled as a task with the class '{C2EBFEAC-F0B8-4F56-941C-B0676E183A21}' (runs on registration).

Software Details

URL:
https://www.winzipper.com
Support:
Installation path:
C:\Program Files\winzipper
Uninstaller:
C:\Program Files\WinZipper\eUninstall.exe
Size:
6.00 MB
Language:
English

WinZipper Executable Details

Primary executable:
winzipper.exe
Name:
WinZipper
Path:
C:\Program Files\winzipper\winzipper.exe
MD5:
a3bd563073759a2d257950b229592e6d
SHA-1:
SHA-256:
Files installed by WinZipper
File Type Filename MD5
DLL
ea072d1ee6cef67b3dfce24a90c89d5f
EXE
52182f5e5d44bf67232933bd2961344d
EXE
539b243749e2296813ec7a5d9e9dca29
DLL
b83d91e59bfb428b18cb16baf60afb5d
DLL
3796b7050f05c509a8e69ca9a4f612fb
DLL
438211b79dcd01799e5fad22f331d6f7
EXE
d4e0fdf5063039965c675cca933f9130
EXE
c3488b5251008e44b162f2fea3b59ef1