1752

Microsoft Windows Operating System

ManySign Inc.

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The file 1752 by ManySign has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by ManySign Inc.)

Product:
Microsoft® Windows® Operating System

Version:
4.9.10586

MD5:
e1eb5bda2a5daa5eb967424be2fa0bb9

SHA-1:
a470ab812f269b037ac06843e4506c44cd0014ea

SHA-256:
da1fb83ff3b8b51e92c760dee24b1c77a51633e08a19068b292b7034bcf00e0d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/19/2025 6:22:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Downloader (M)
16.9.6.0

File size:
753.3 KB (771,392 bytes)

Product version:
4.9.10586

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
y05epac.exe

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\1752

Digital Signature
Signed by:

Authority:
ManySign Inc.

Valid from:
2/27/2016 9:36:13 AM

Valid to:
2/26/2017 9:36:13 AM

Subject:
E=contact@manysign.com, OU=ManySign Authority, O=ManySign Inc., L=Lansing, S=Michigan, C=US, CN=ManySign

Issuer:
E=contact@manysign.com, OU=ManySign Authority, O=ManySign Inc., L=Lansing, S=Michigan, C=US, CN=ManySign

Serial number:
00A9CE1EFF3DF92E00

File PE Metadata
Compilation timestamp:
4/3/2016 10:55:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:sNwFdTCEYORrawk52fjel/wT0z4Pzu2bqdHcjTzKKhvrBJeC3x0WahxR2:XTCEqtQw4PRe9c+GBUC3xlahO

Entry address:
0xBA04E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
740 KB (757,760 bytes)

Remove 1752 - Powered by Reason Core Security