LiveUpdate.exe

System Cleaner

Pointstone Software, LLC

The application LiveUpdate.exe by Pointstone Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program System Cleaner 7 by Pointstone Software, LLC. While running, it connects to the Internet address pointstone.com on port 80 using the HTTP protocol.
Publisher:
Pointstone Software, LLC  (signed and verified)

Product:
System Cleaner

Description:
Live Update

Version:
6.0.0.0

MD5:
f961a43392b8d3efbca8bca98810658d

SHA-1:
49a409342a502baf1bbfff0017bc60fd63a35e5f

SHA-256:
1afabefe63d5a414f54a672cf3cfa2baf0a497308b061e7c8d2a8c201e850256

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 5:44:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Pointstone
16.11.12.16

File size:
268.5 KB (274,976 bytes)

Copyright:
Copyright © 1997 - 2016 Pointstone Software, LLC. All rights reserved.

Trademarks:
System Cleaner is a registered trademark of Pointstone Software, LLC. (United States Patent and Trademark Office registration number 2926385)

Original file name:
LiveUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pointstone\system cleaner 7\liveupdate.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
11/11/2014 6:00:00 PM

Valid to:
11/12/2019 5:59:59 PM

Subject:
CN="Pointstone Software, LLC", O="Pointstone Software, LLC", L=Newark, S=DE, PostalCode=19713, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
1E600E539078A378196FBC5627EB6553

File PE Metadata
Compilation timestamp:
11/8/2016 5:54:10 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:UDZ/xRSqDdQHM1U6ak06+jzaFAPyqF2tja:cZpIWQHM1U6a2ja

Entry address:
0xE4A8

Entry point:
55, 8B, EC, B9, 08, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, B8, 5C, C4, 40, 00, E8, 3F, 2D, FF, FF, 33, C0, 55, 68, 36, E7, 40, 00, 64, FF, 30, 64, 89, 20, 8D, 45, E8, E8, 01, 3E, FF, FF, 8B, 45, E8, BA, 50, E7, 40, 00, 8B, 08, FF, 51, 0C, A1, 7C, 2A, 41, 00, 8B, 00, E8, 08, 3D, FF, FF, A1, 7C, 2A, 41, 00, 8B, 00, B2, 01, E8, 22, 3D, FF, FF, A1, 7C, 2A, 41, 00, 8B, 00, BA, 68, E7, 40, 00, E8, D9, 3C, FF, FF, E8, BC, 3D, FF, FF, 8B, 10, FF, 52, 08, 8B, 10, FF, 52, 50, 8B, 15, 80, F1, 40, 00, 88, 02, 8D, 45...
 
[+]

Entropy:
7.0556

Developed / compiled with:
Microsoft Visual C++

Code size:
51.5 KB (52,736 bytes)

The file LiveUpdate.exe has been discovered within the following program.

System Cleaner 7  by Pointstone Software, LLC
Publisher's description - “Fix your PC's problems, and help prevent them from recurring with System Cleaner's suite of maintenance tools. System Cleaner restores your PC's performance, frees up wasted disk space, prevents registry corruption and protects your online privacy. Your PC is slowing down.”
www.systemcleaner.com
45% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to pointstone.com  (108.61.26.20:80)

Remove LiveUpdate.exe - Powered by Reason Core Security