dataunit ffu-tatra3.exe

DataUnit FFU-Tatra3 2.3.29.0

Starkey Hearing Technologies

The application dataunit ffu-tatra3.exe, “Self-extracting EXE for Deployment of DataUnit FFU-Tatra3.” by Starkey Hearing Technologies has been detected as a potentially unwanted program by 3 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Starkey Hearing Technologies  (signed and verified)

Product:
DataUnit FFU-Tatra3 2.3.29.0

Description:
Self-extracting EXE for Deployment of DataUnit FFU-Tatra3.

Version:
2.3.29.0

MD5:
06c5bbf44509043377127451a0f6d2dc

SHA-1:
5baa337042f06bdabe4e15acb518f7f32777fe4a

SHA-256:
f4d5053ced3302b3a5b8c2d51d9d4ea36e01e92db41320dd80665c183f700c6f

Scanner detections:
3 / 68

Status:
Potentially unwanted

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
4/19/2024 11:18:29 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Dr.Web
Trojan.KillFiles.23695
9.0.1.05190

F-Secure
Adware.BrowseFox.BY
5.13.68

Rising Antivirus
PE:Malware.XPACK-LNR/Heur!1.5594
23.00.65.15304

File size:
448.5 KB (459,240 bytes)

Product version:
2.3.29.0

Copyright:
Copyright (C) 2013, Starkey Laboratories, Inc. ALL RIGHTS RESERVED

Trademarks:
Packed with Paquet Builder, see http://www.gdgsoft.com

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\ProgramData\inspiresetup 13.0.204.0\setup\dataunits\ffu-tatra3\dataunit ffu-tatra3.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/15/2012 1:00:00 AM

Valid to:
10/16/2015 12:59:59 AM

Subject:
CN=Starkey Hearing Technologies, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Starkey Hearing Technologies, L="Eden Prairie ", S=Minnesota, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
26AC337847339E5B6CC0742871271AF3

File PE Metadata
Compilation timestamp:
1/9/2015 8:26:28 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.50

CTPH (ssdeep):
12288:lZ3MNCrwNozU0UYYc2gG+XcK5teov3wEYFhm+y:LMNCsNoU0UYYHOcK5YorpV

Entry address:
0xA170

Entry point:
55, 89, E5, 6A, FF, 68, 64, 09, 41, 00, 68, 68, B8, 40, 00, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 83, EC, 50, 53, 56, 57, 89, 65, E8, 68, 00, 00, 00, 02, E8, 40, 2F, 00, 00, 59, A3, A4, 20, 41, 00, E8, 35, 1A, 00, 00, 85, C0, 75, 0D, 6A, 01, E8, 6A, 1C, 00, 00, 59, E9, C2, 00, 00, 00, C7, 45, FC, 00, 00, 00, 00, E8, 68, 1C, 00, 00, E8, 23, 1D, 00, 00, E8, 6E, 1D, 00, 00, E8, 79, 21, 00, 00, E8, 14, 22, 00, 00, BB, BC, 16, 41, 00, 81, FB, BC, 16, 41, 00, 73, 0D, FF, 13, 83, C3, 04, 81, FB...
 
[+]

Entropy:
7.8440  (probably packed)

Code size:
59.5 KB (60,928 bytes)

Remove dataunit ffu-tatra3.exe - Powered by Reason Core Security