Threat Database Adware Hprewriter2

Hprewriter2

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 263
First Seen: August 19, 2016
Last Seen: September 7, 2026
OS(es) Affected: Windows

When online shopping you may be offered to install a program named HPREWRITER2, which promises to find the best prices and coupons for the merchandising or service you are looking for. HPREWRITER2 features may sound interesting and useful. However, HPREWRITER2 may install an unwanted browser plugin to your favored Web browser automatically, no matter if it is Google Chrome, Opera, Internet Explorer or Mozilla Firefox. The main function of HPREWRITER2 is to display a flood of advertisements that besides been annoying, may disrupt the tasks you are trying to accomplish on your computer. These advertisements that may appear as coupons, pop-ups or banners may cover the Web pages you want to visit preventing you from viewing what you need.

Besides, they may try to convince you to purchase a fake security program, install bogus updates and access unsafe content so that they can earn pay-per-click income. The big amount of advertisements displayed by HPREWRITER2 may slow down your machine, and even make it crash. If you want to prevent applications such as HPREWRITER2 from entering your computer, you need to choose 'Custom' or 'Advanced' installation methods when downloading free applications to your machine. Otherwise, you will not be able to know that there may be additional programs bundled with it. You can stop the unwanted advertisements displayed by HPREWRITER2 removing this application from your computer with a malware removal utility.

Analysis Report

General information

Family Name: Adware.Superweb.CA
Signature status: Self Signed

Known Samples

MD5: 61456cc87e961444bab5b61afa53e7b7
SHA1: 2b97a48841e31ad2d2f675e36849981eb8969ed5
SHA256: 221D8181CE3DC3E76B9DA102EB68A5FBF7BC2DE086669B24C8E4969EF75BF4CD
File Size: 1.03 MB, 1031904 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version 1.0.5961.14542
Product Version 1.0.5961.14542

Digital Signatures

Signer Root Status
Fresh Sync VeriSign Class 3 Code Signing 2010 CA Self Signed

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 4,873
Potentially Malicious Blocks: 987
Whitelisted Blocks: 3,725
Unknown Blocks: 161

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? x ? x ? x ? ? ? ? ? ? x ? x ? ? x x ? ? ? x x x ? ? ? x ? ? x ? ? x x ? x x ? ? ? ? x ? x ? ? ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 x x x 1 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x x 0 0 x x 0 0 0 x 0 x x 0 x x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 x x 0 0 0 0 0 x x x x 0 0 0 x x 0 0 x x 0 x 0 0 x x x x 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x x x 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 x 0 x 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 x x 0 0 x 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x x 0 x x 0 0 x x x x 0 0 0 x x x 0 x x 0 x 0 x x 0 x x x 0 0 0 0 x x x x x 0 0 x x 0 0 0 x 0 0 0 0 0 0 x x 0 x x 0 x x 0 x x x 0 x x 0 0 x 0 0 x 0 0 0 0 0 x x x x 0 0 0 x x 0 0 0 0 0 x x 0 0 0 x x x x 0 x x 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x x ? x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 x 0 0 x 0 0 0 x x x x 0 x 0 x 0 x x x x x 0 x ? 0 ? x ? x ? x ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 x 0 0 0 0 x x 0 x x 0 0 x 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 x 0 0 0 1 x x 0 0 0 x 0 0 0 x x 0 x x x 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x 0 0 x x 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x x 0 x x 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x 0 0 0 x 0 x 0 x x x x 0 0 x 0 0 0 0 0 0 x 0 0 0 x x x x x x x x 0 x x 0 0 x x 0 0 x x 0 x 0 0 x 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 x x x x x x 0 0 x x 0 0 0 x 0 0 0 x x 0 x 0 x x 0 0 0 x 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 x x 0 0 x x 0 x x x 0 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x 0 x 0 0 x x x x ? 0 0 x x x x 0 0 0 0 x 0 0 0 0 x x x x x 0 x ? x 0 0 0 x ? ? 0 x ? 0 0 0 x 0 0 0 ? x 0 x 0 x x x x x x 0 0 0 0 x 0 ? ? x ? ? ? ? ? 0 0 x 0 x 0 x x 0 x x 0 0 x 0 x x x x x ? 0 0 0 ? ? x ? ? ? x 0 ? ? ? 0 0 x x x ? x x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 ? ? ? x ? x ? x x x x x x ? ? ? 0 0 x ? x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 x 0 x 0 0 0 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 x x x x x 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 x 0 x x 0 0 0 0 x 0 0 0 x 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 x x x x 0 0 0 x x x 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 x 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 x 1 x 1 1 0 1 0 0 x 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x x 0 x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x 0 0 x x 0 0 x 0 x 0 0 x 0 0 0 x x 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 x 0 x x x x 0 0 x 0 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 x 0 x x 0 0 x 0 x 0 x x x 0 x 0 x x 0 x x 0 0 x 0 x x 0 x x 0 0 x x x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Superweb.CA

Windows API Usage

Category API
User Data Access
  • GetComputerName