PmmUpdate.exe

EgisTec In-Product Service

Egis Technology Inc.

The executable PmmUpdate.exe, “PMM Update Application” has been detected as malware by 23 anti-virus scanners. It runs as a scheduled task under the Windows Task Scheduler named PMMUpdate triggered to execute each time a user logs in.
Publisher:
Egis Technology Inc.

Product:
EgisTec In-Product Service

Description:
PMM Update Application

Version:
1.1.41.0

MD5:
7ef9c38d0db4f85bd4367dcf0684e8ab

SHA-1:
14c11029d889ebd799a35b7cb6eb382734b49ad7

SHA-256:
3346df0f910f543a2b7873ed3e6f0bfc9148583b9634717f5c8f03fac4bfdd1e

Scanner detections:
23 / 68

Status:
Malware

Analysis date:
4/19/2024 11:01:15 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Worm.Nimda.O
5763971

Avira AntiVirus
W32/Chir.B
7.11.30.172

Arcabit
Win32.Worm.Nimda.O
1.0.0.425

avast!
Win32:Runouce-E [Trj]
150602-1

AVG
Win32/Chir.B@mm
2015.0.4355

Bitdefender
Win32.Worm.Nimda.O
1.0.20.940

Clam AntiVirus
WIN.Worm.Brontok
0.98/20657

Dr.Web
Win32.Runonce.6652
9.0.1.05190

Emsisoft Anti-Malware
Win32.Worm.Nimda.O
10.0.0.5366

Fortinet FortiGate
W32/Runouce.B@mm
7/7/2015

F-Secure
Win32.Worm.Nimda.O
5.14.151

G Data
Win32.Worm.Nimda
15.7.25

IKARUS anti.virus
Email-Worm.Win32.Runouce
t3scan.1.9.5.0

Kaspersky
Email-Worm.Win32.Runouce
15.0.0.543

McAfee
Virus.W32/Chir.gen@MM!remanants
17.6.569.0

Microsoft Security Essentials
Threat.Undefined
1.201.1110.0

MicroWorld eScan
Win32.Worm.Nimda.O
16.0.0.564

Norman
Win32.Worm.Nimda.O
07.07.2015 03:10:29

nProtect
Win32.Worm.Nimda.O
15.07.07.01

Panda Antivirus
W32/Chir.P.worm
15.07.07.04

Rising Antivirus
PE:Worm.Runouce!1.9DC6
23.00.65.15705

Sophos
W32/Chir-B
4.98

VIPRE Antivirus
Threat.4672667
40786

File size:
448.9 KB (459,628 bytes)

Product version:
1.1.41.0

Copyright:
Copyright ©2008 Egis Technology Inc. All rights reserved.

Original file name:
PmmUpdate.exe

File type:
Executable application (Win64 EXE)

Common path:
C:\Program Files\egistec ips\pmmupdate.exe

File PE Metadata
Compilation timestamp:
3/28/2011 2:47:14 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:KqfylkVrNoYUEv1kv5M6OsnaJejrTjCzT6wG5XOrZ8wBMB4WtKKfcQZ5ly35QO2u:Kqo7cQZ5lyJR14i4mvunk

Entry address:
0x40068641

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, F8, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
4.9914

Code size:
114 KB (116,736 bytes)

Scheduled Task
Task name:
PMMUpdate

Trigger:
Logon (Runs on logon)


Remove PmmUpdate.exe - Powered by Reason Core Security