patchw32.dll

RTPatch

WhiteSmoke Inc

The module patchw32.dll, “RTPatch Executable” by WhiteSmoke Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Pocket Soft, Inc.  (signed by WhiteSmoke Inc)

Product:
RTPatch

Description:
RTPatch Executable

Version:
7.00

MD5:
c6066581d8183f362234c1b7381fe285

SHA-1:
ccc273ed636a70a06eb28a0398f8cd3d95dbbbeb

SHA-256:
679391cdbd3794a54f4313ddd1d223a24b29970d60b4e89a1405e37a22cd9de2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 10:41:00 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WhiteSmoke.PocketSoft (M)
15.12.20.10

File size:
202.8 KB (207,672 bytes)

Product version:
7.00

Copyright:
(C) Copyright Pocket Soft, Inc., 2002. All Rights Reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\windows\syswow64\patchw32.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/17/2007 6:00:00 PM

Valid to:
6/17/2008 5:59:59 PM

Subject:
CN=WhiteSmoke Inc, OU=R&D, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WhiteSmoke Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6909B96020B7E23C83DA2D03280AA61E

File PE Metadata
Compilation timestamp:
12/3/2002 1:01:03 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.55

CTPH (ssdeep):
6144:8oJxWpvYGqN601s8CGafZO3h8HMV61zAhnSWOS7aB8JLpa:H3tGbPGaI3h8BAhnz3Y

Entry address:
0x20E8C

Entry point:
55, 8B, EC, 56, 57, BF, 01, 00, 00, 00, 8B, 75, 0C, 3B, F7, 0F, 85, 93, 00, 00, 00, 01, 3D, 88, 0A, 03, 10, 83, FE, 01, 74, 05, 83, FE, 02, 75, 27, 8B, 0D, D4, D8, 02, 10, 85, C9, 74, 0B, FF, 75, 10, 56, FF, 75, 08, FF, D1, 8B, F8, 85, FF, 74, 20, FF, 75, 10, 56, FF, 75, 08, E8, 0A, FF, FF, FF, 8B, F8, 85, FF, 74, 12, FF, 75, 10, 56, FF, 75, 08, E8, E8, 9A, FE, FF, 8B, F8, 85, FF, 75, 0A, 83, FE, 01, 75, 05, E8, 08, 22, 00, 00, 85, F6, 74, 05, 83, FE, 03, 75, 2B, FF, 75, 10, 56, FF, 75, 08, E8, D3, FE, FF...
 
[+]

Entropy:
6.5965

Developed / compiled with:
Microsoft Visual C++

Code size:
160 KB (163,840 bytes)

Remove patchw32.dll - Powered by Reason Core Security