AutoUpdate.EXE

Amadeus Automatic Update

Amadeus

Publisher:
Amadeus  (signed and verified)

Product:
Amadeus Automatic Update

Description:
Automatic Update Service

Version:
2, 6, 400, 1

MD5:
2293c1d3f5d54be8ba8e97aad5714e13

SHA-1:
96694b21d8b5a4b1fe1318a9bbbc6ae602956a3c

SHA-256:
c5ea01d3c9ca0176e7433bf3b97349dd0aac17c97a83637f25f387d6a6f4b95b

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/23/2024 11:10:26 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
Optional.Amadeus
188838

Prevx
Heuristic: Suspicious Self Modifying File
3.0.2

Vba32 AntiVirus
suspected of Win32.BrokenEmbeddedSignature
16.02.03

File size:
124.4 KB (127,400 bytes)

Product version:
2, 6, 400, 0

Copyright:
Copyright 2001

Original file name:
AutoUpdate.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\downloaded Program Files\autoupdate.exe

Digital Signature
Signed by:

Authority:
Amadeus

Valid from:
9/1/2003 2:26:11 PM

Valid to:
9/1/2018 2:36:11 PM

Subject:
CN=amadeus sign in certificate, OU=Amadeus Data Processing, O=Amadeus, L=Erding, S=Bayern, C=DE, E=orouviere@amadeus.net

Issuer:
CN=Amadeus Root CA, OU=Amadeus Data Processing, O=Amadeus, L=Erding, S=Bayern, C=DE, E=amadeus@amadeus.net

Serial number:
6113B55900000000001C

File PE Metadata
Compilation timestamp:
11/6/2007 10:28:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:JGmVMFrmt5cU2hhCZfxXQPGHuM1TTlI+uXX7N:JGtBpP8ZfxXQPwTlIRHB

Entry address:
0xFDB4

Entry point:
55, 8B, EC, 6A, FF, 68, D8, 27, 41, 00, 68, 2A, FF, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, 84, 25, 41, 00, 59, 83, 0D, 7C, CE, 41, 00, FF, 83, 0D, 80, CE, 41, 00, FF, FF, 15, 90, 25, 41, 00, 8B, 0D, 74, CE, 41, 00, 89, 08, FF, 15, 94, 25, 41, 00, 8B, 0D, 70, CE, 41, 00, 89, 08, A1, 98, 25, 41, 00, 8B, 00, A3, 78, CE, 41, 00, E8, 34, 01, 00, 00, 39, 1D, D8, C9, 41, 00, 75, 0C, 68, 54, FF, 40, 00, FF, 15, 9C, 25...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
68 KB (69,632 bytes)

ActiveX Install
Name:
{051FE707-9706-11D5-A836-000102A7C938}


Scan AutoUpdate.EXE - Powered by Reason Core Security