pcupdaterapi.exe

Windows Setup API

Maximum Publishing LLC

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The application pcupdaterapi.exe, “Windows Setup API” by Maximum Publishing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Microsoft Corporation  (signed by Maximum Publishing LLC)

Product:
Microsoft® Windows® Operating System

Description:
Windows Setup API

Version:
6.0.6000.16386 (vista_rtm.061101-2205)

MD5:
b33b4c8297aadf06f3b39895e25306aa

SHA-1:
6ddda193a565048af5c5e0cb745af57bb02a44df

SHA-256:
b1ee0133284c02eb31f17d1b57d0c154ee3f85450012d99425d27730a999ee4d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 5:51:22 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.PCBugDoctor.Optional.Installer.Meta (L)
15.11.28.2

File size:
79.2 KB (81,120 bytes)

Product version:
6.0.6000.16386

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
SETUPAPI.DLL

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pc updater\vista\pcupdaterapi.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/25/2007 1:00:00 AM

Valid to:
9/25/2010 12:59:59 AM

Subject:
CN=Maximum Publishing LLC, OU=of Corperations, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Maximum Publishing LLC, L=Lewes, S=Delaware, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
30CE1714CDADA71FE0A22F352DFA0E3D

File PE Metadata
Compilation timestamp:
11/2/2006 8:33:23 AM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

CTPH (ssdeep):
768:fBVg66plPNWeHXPKT048dBlHSS+BN8Z3+b26v82BSOe9oKSJ2SLD0BEZWk2agbC:JVZqlP8O4SrSSo8Z3+y6vF4O7Wh1C

Entry address:
0x62AF

Entry point:
E8, 2A, 06, 00, 00, E9, B6, FD, FF, FF, CC, CC, CC, CC, CC, FF, 25, 84, 11, 00, 01, CC, CC, CC, CC, CC, CC, FF, 25, E4, 11, 00, 01, CC, CC, CC, CC, CC, 3B, 0D, B0, 81, 00, 01, 75, 02, F3, C3, E9, 84, 06, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 04, 2B, C8, 1B, C0, F7, D0, 23, C8, 8B, C4, 25, 00, F0, FF, FF, 3B, C8, 72, 0A, 8B, C1, 59, 94, 8B, 00, 89, 04, 24, C3, 2D, 00, 10, 00, 00, 85, 00, EB, E9, CC, CC, CC, CC, CC, FF, 25, 8C, 11, 00, 01, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
5.1595

Code size:
26.5 KB (27,136 bytes)

Remove pcupdaterapi.exe - Powered by Reason Core Security