ascupgrade.exe

Upgrader

IObit

The executable ascupgrade.exe, “Advanced SystemCare 7 Upgrader” has been detected as malware by 7 anti-virus scanners.
Publisher:
IObit

Product:
Upgrader

Description:
Advanced SystemCare 7 Upgrader

Version:
7.0.0.30

MD5:
cc2c12f85141fe75867dbb80af82e2fd

SHA-1:
0a9573863ef19625a55a5b273e44454e0f1249bf

SHA-256:
fda206a5e30d7d4419b6e465ba1fff8aa29aeb33e3b87c488b3a4c1504f7a9e9

Scanner detections:
7 / 68

Status:
Malware

Analysis date:
4/18/2024 4:20:57 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Malware.Heur.HK0@bq16!jjj
928

Avira AntiVirus
HEUR/Malware
7.11.163.92

Bitdefender
Gen:Malware.Heur.HK0@bq16!jjj
1.0.20.1015

Emsisoft Anti-Malware
Gen:Malware.Heur.HK0@bq16!jjj
8.14.07.22.09

F-Secure
Gen:Malware.Heur.HK0@bq16!jjj
11.2014-22-07_3

G Data
Gen:Malware.Heur.HK0@bq16!jjj
14.7.24

MicroWorld eScan
Gen:Malware.Heur.HK0@bq16!jjj
15.0.0.609

File size:
535.5 KB (548,352 bytes)

Product version:
7.0.0.0

Copyright:
Copyright(c) 2005-2013

Trademarks:
IObit

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\iobit\advanced systemcare 7\ascupgrade.exe

File PE Metadata
Compilation timestamp:
4/30/2014 11:43:11 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:EmKnm5Wl4sJb8NK3lLMJNGAKYbdrOj888888888888W88888888888R:zKnMWl6NKuJnKYbq

Entry address:
0x6A88C

Entry point:
55, 8B, EC, 83, C4, E0, 53, 56, 57, 33, C0, 89, 45, E0, 89, 45, E4, 89, 45, EC, 89, 45, E8, B8, 28, 91, 46, 00, E8, CF, D1, F9, FF, 33, C0, 55, 68, D8, AA, 46, 00, 64, FF, 30, 64, 89, 20, 33, C0, 55, 68, 72, AA, 46, 00, 64, FF, 30, 64, 89, 20, 8D, 55, E8, B8, 01, 00, 00, 00, E8, D2, 8A, F9, FF, 8B, 45, E8, 8D, 55, EC, E8, CF, FE, F9, FF, 8B, 45, EC, BA, F4, AA, 46, 00, E8, FE, B7, F9, FF, 0F, 85, 01, 01, 00, 00, A1, 4C, CA, 46, 00, C6, 00, 00, BA, 14, AB, 46, 00, B8, 38, AB, 46, 00, E8, 49, B9, FF, FF, BA...
 
[+]

Entropy:
6.4836

Developed / compiled with:
Microsoft Visual C++

Code size:
420 KB (430,080 bytes)

Remove ascupgrade.exe - Powered by Reason Core Security