DUControl.exe

DirectUpd@te control

William Levra-Juillet

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘DUControl’.
Publisher:
WildUP - William Levra-Juillet  (signed by William Levra-Juillet)

Product:
DirectUpd@te control

Description:
DirectUpd@te - Control tool

Version:
4.7.6 build 137 - 32bits

MD5:
a713fa50dc581444b74cea042f0f7765

SHA-1:
0a05d20c4dfa163772ee04aa94bd9f3d6005f07b

SHA-256:
8c88f307474e7ff4401e12a96fba68af0b162333f391dbe2c883bd5cb984e4e0

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 3:43:32 AM UTC  (today)

File size:
50.6 KB (51,776 bytes)

Product version:
4.7.6 build 137 - 32bits

Copyright:
©2000-2013 William Levra-Juillet

Original file name:
DUControl.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\directupdate v4\ducontrol.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/8/2012 2:00:00 AM

Valid to:
8/9/2015 1:59:59 AM

Subject:
CN=William Levra-Juillet, O=William Levra-Juillet, STREET=101 Roebuck Castle, L=Clonskeagh, S=Dublin, PostalCode=14, C=IE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
241D59C1D0F0AA4995A22C1E2A267679

File PE Metadata
Compilation timestamp:
5/31/2015 11:01:32 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
768:hQR7IKcIfiz8Bl6ZmAtK96gNUuOwYfozW2zXVXF0n0bNDr2YNMEN:hQVtoil6ZmWK9dN1OwFjXVVOAnPHN

Entry address:
0x3AB5

Entry point:
E8, 8E, 04, 00, 00, E9, 36, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F8, 71, 40, 00, 89, 0D, F4, 71, 40, 00, 89, 15, F0, 71, 40, 00, 89, 1D, EC, 71, 40, 00, 89, 35, E8, 71, 40, 00, 89, 3D, E4, 71, 40, 00, 66, 8C, 15, 10, 72, 40, 00, 66, 8C, 0D, 04, 72, 40, 00, 66, 8C, 1D, E0, 71, 40, 00, 66, 8C, 05, DC, 71, 40, 00, 66, 8C, 25, D8, 71, 40, 00, 66, 8C, 2D, D4, 71, 40, 00, 9C, 8F, 05, 08, 72, 40, 00, 8B, 45, 00, A3, FC, 71, 40, 00, 8B, 45, 04, A3, 00, 72, 40, 00, 8D, 45, 08, A3, 0C, 72, 40...
 
[+]

Code size:
13 KB (13,312 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DUControl

Command:
"C:\Program Files\directupdate v4\ducontrol.exe"


Scan DUControl.exe - Powered by Reason Core Security