osu!.exe

osu!

Dean Herbert

This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler. This is the uninstaller utility registered in the Windows Control Panel for the program osu! by ppy Pty Ltd. The file has been seen being downloaded from m1.ppy.sh and multiple other hosts.
Publisher:
ppy  (signed by Dean Herbert)

Product:
osu!

Version:
1.3.3.7

MD5:
7666a8321b222481e2c8c646c2c89e46

SHA-1:
f7c19567471efa33056232db802d04ec13c77045

SHA-256:
4716789aea4fe93a9beb367c8cd6867adeb8fb3360c97339663dcf0f0252d8e6

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 4:47:45 PM UTC  (today)

File size:
3 MB (3,132,488 bytes)

Product version:
1.3.3.7

Copyright:
ppy powered 2007-2014

Original file name:
osu!.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\osu!\osu!.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
9/28/2012 7:00:00 AM

Valid to:
9/29/2015 6:59:59 AM

Subject:
CN=Dean Herbert, O=Dean Herbert, STREET=41 Gregory Street, STREET=Wembley, L=Perth, S=WA, PostalCode=6014, C=AU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00FD15503D4AF404C84200F5CCC3C99380

File PE Metadata
Compilation timestamp:
10/15/2014 12:11:18 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:1MRxp7bheg+vQOjsVYbw6ooaep6BFq1Tm2Neh3pNc:1MRxp7bhX+Y3ww6ooaepDp

Entry address:
0x1D9E56

Entry point:
FF, 25, 46, 9E, 5D, 00, 00, 00, 5F, 43, 6F, 72, 45, 78, 65, 4D, 61, 69, 6E, 00, 6D, 73, 63, 6F, 72, 65, 65, 2E, 64, 6C, 6C, 00, 79, 08, 03, 00, 7B, 7A, 7D, 01, 00, F0, 03, 00, 69, 08, 03, 00, 00, F0, 03, 00, EC, BD, 09, 7C, 1D, 55, BD, 38, 7E, 43, 0B, 94, 96, 4D, 2C, 8B, 50, 61, 52, 96, 26, 90, A4, 59, BA, 06, A6, 25, 6B, 1B, 9A, CD, 24, 6D, 05, 8A, 61, 72, EF, 24, 19, 72, EF, CC, 65, 66, 6E, D2, 4B, AD, B8, 20, 3C, 56, 45, C4, 9F, BB, F8, 50, DC, 15, 14, 65, 55, 11, 70, 03, 45, 40, 05, 17, 14, 50, 14, 70...
 
[+]

Code size:
2.8 MB (2,928,128 bytes)

Program Uninstaller
Program name:
osu!

Display publisher:
ppy Pty Ltd

Display version:
latest

Uninstall string:
C:\Program Files (x86)\osu!\osu!.exe -uninstall


Scheduled Task
Task name:
{AE5339D5-3894-4E0C-962B-05EEF242811D}

Trigger:
Registration (Runs on registration)


The file osu!.exe has been discovered within the following program.

osu!  by peppy
osu.ppy.sh
About 1% of users remove it
 
Powered by Should I Remove It?

The file osu!.exe has been seen being distributed by the following 3 URLs.

http://m1.ppy.sh/.../osu!install.exe

Scan osu!.exe - Powered by Reason Core Security