RealUpgrade.exe

RealUpgrade

RealNetworks, Inc.

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
RealNetworks, Inc.  (signed and verified)

Product:
RealUpgrade

Description:
RealUpgrade Launcher

Version:
16.0.3.51

MD5:
2a356fa2650e30e139f0476979548bf6

SHA-1:
6e80357d9a18f4143acb539b215ab078b39d4327

SHA-256:
c11bc218a72a6978e0590fd09cc0edd8800b497441777f2a282daf8f14f5ab76

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/20/2024 1:52:44 AM UTC  (today)

Scan engine
Detection
Engine version

Boost by Reason
UnneededApp.Task.RealNetworks.L
164288

File size:
183.6 KB (187,984 bytes)

Product version:
16.0.3.51

Copyright:
Copyright © RealNetworks, Inc. 1995-2013

Original file name:
RealUpgrade.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\real\realupgrade\realupgrade.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
7/25/2013 5:00:00 PM

Valid to:
8/15/2015 4:59:59 PM

Subject:
CN="RealNetworks, Inc.", OU=MS&S, O="RealNetworks, Inc.", L=Seattle, S=Washington, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
72B64DF3DBCC1FB70C7858961B8A5BBA

File PE Metadata
Compilation timestamp:
8/14/2013 5:13:02 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:zSQXQL6wPoDqS0QYU8oiOQnQhWS7pvnaCOSxKpf3fucBl:zSQXOPo2SniOQnQkS7pfaCOSc/r

Entry address:
0x4098

Entry point:
E8, 97, 04, 00, 00, E9, 63, FD, FF, FF, 3B, 0D, 0C, 43, 41, 00, 75, 02, F3, C3, E9, 1E, 05, 00, 00, CC, FF, 25, 6C, F2, 40, 00, FF, 25, 60, F2, 40, 00, FF, 25, 54, F2, 40, 00, 6A, 14, 68, 28, 2B, 41, 00, E8, E0, 03, 00, 00, FF, 35, 54, 4D, 41, 00, 8B, 35, 5C, F1, 40, 00, FF, D6, 89, 45, E4, 83, F8, FF, 75, 0C, FF, 75, 08, FF, 15, F4, F1, 40, 00, 59, EB, 64, 6A, 08, E8, E9, 05, 00, 00, 59, 83, 65, FC, 00, FF, 35, 54, 4D, 41, 00, FF, D6, 89, 45, E4, FF, 35, 50, 4D, 41, 00, FF, D6, 89, 45, E0, 8D, 45, E0, 50...
 
[+]

Entropy:
5.7568

Code size:
53 KB (54,272 bytes)

4 Scheduled Tasks
Task name:
RealPlayerRealUpgradeLogonTaskSID

Trigger:
Logon (Runs on logon)

Task name:
RealUpgradeLogonTaskSID

Trigger:
Logon (Runs on logon)

Task name:
RealPlayerRealUpgradeScheduledTaskSID

Trigger:
Daily (Runs daily at 2.09)

Task name:
RealUpgradeScheduledTaskSID

Trigger:
Daily (Runs daily at 1:04)


Windows Firewall Allowed Program
Name:
C:\Program Files\Real\RealUpgrade\RealUpgrade.exe


Scan RealUpgrade.exe - Powered by Reason Core Security