65e0.tmp

Useful Software

This is part of the Verti bundle installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The file 65e0.tmp by Useful Software has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is also typically executed from the user's temporary directory.
Publisher:
Useful Software  (signed and verified)

Version:
1.0.0.7

MD5:
0f3097c25afd869c1c81106d5b648a6b

SHA-1:
f892b2ede7c81befea22a3a93de03158bb11470d

SHA-256:
5976dc1fdda63934cf2ba53ba53c4739b78b9a8a914ed3666f11b379d35f9d44

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 9:54:18 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Verti.UsefulSoftware (M)
15.12.16.9

File size:
404.1 KB (413,784 bytes)

Product version:
1.0.0.7

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\65e0.tmp

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/13/2014 5:00:00 PM

Valid to:
12/16/2014 4:59:59 PM

Subject:
CN=Useful Software, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Useful Software, L=Bellevue, S=Washington, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
7DB9B4E338BDCF4F909F675C098B0E76

File PE Metadata
Compilation timestamp:
8/8/2014 10:11:03 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
12288:y3zjz+FsMQzoYjMAFULqE1cxfro7zF1W+LVO5p6aITxWfpBkYzl:uSDAFULqE1cxfro7zF1W+LVO5p6aITC7

Entry address:
0x258D1

Entry point:
E8, AA, AE, 00, 00, E9, 7F, FE, FF, FF, 6A, 08, 68, 88, 83, 45, 00, E8, 89, 00, 00, 00, FF, 35, 7C, DA, 45, 00, FF, 15, F8, E1, 43, 00, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 01, 00, 00, 00, CC, 6A, 08, 68, 68, 83, 45, 00, E8, 51, 00, 00, 00, E8, 9B, 2F, 00, 00, 8B, 40, 78, 85, C0, 74, 16, 83, 65, FC, 00, FF, D0, EB, 07, 33, C0, 40, C3, 8B, 65, E8, C7, 45, FC, FE, FF, FF, FF, E8, 61, AF, 00, 00, CC, E8, 73, 2F, 00, 00, 8B, 40, 7C, 85, C0...
 
[+]

Entropy:
6.4552

Code size:
243.5 KB (249,344 bytes)

Remove 65e0.tmp - Powered by Reason Core Security