updatesrv.exe

MY SECURITY CENTER LTD

The application updatesrv.exe, “MYSecurityCenter Update Service” by MY SECURITY CENTER has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “MYSecurityCenter Update Service”.
Publisher:
MYSecurityCenter  (signed by MY SECURITY CENTER LTD)

Product:
MYSecurityCenter

Description:
MYSecurityCenter Update Service

Version:
17.20.0.852 102308

MD5:
1db7d1f7b6f3bc4a9db54998027dbe3b

SHA-1:
65021fb713f2e7f1a1aa76bdc3c83d89452e88bb

SHA-256:
39fc02031e3827dd4494470bcab0bf7750aed5c3905cb7383ed7cdfa3baadc75

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/23/2024 7:16:47 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic
16.2.15.13

File size:
51.8 KB (53,080 bytes)

Product version:
17.20.0.852 102308

Copyright:
©MYSecurityCenter

Original file name:
updatesrv.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mysecuritycenter\myinternetsecurity\updatesrv.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/17/2012 2:00:00 AM

Valid to:
7/21/2015 2:00:00 PM

Subject:
CN=MY SECURITY CENTER LTD, O=MY SECURITY CENTER LTD, L=West Drayton, C=GB

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
02B405245A6E01DE7848F7C55FC3BCC7

File PE Metadata
Compilation timestamp:
10/7/2013 11:13:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
768:+gOYllS/o0yYMmxOiI6+EHnNgn9g1mSWi8JEOa+ChTPUO6Kgn8:+gOcl6o0R30iIRcNlpOihj8K

Entry address:
0x7512

Entry point:
E8, F3, 04, 00, 00, E9, 24, FD, FF, FF, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, F0, B2, 40, 00, 89, 0D, EC, B2, 40, 00, 89, 15, E8, B2, 40, 00, 89, 1D, E4, B2, 40, 00, 89, 35, E0, B2, 40, 00, 89, 3D, DC, B2, 40, 00, 66, 8C, 15, 08, B3, 40, 00, 66, 8C, 0D, FC, B2, 40, 00, 66, 8C, 1D, D8, B2, 40, 00, 66, 8C, 05, D4, B2, 40, 00, 66, 8C, 25, D0, B2, 40, 00, 66, 8C, 2D, CC, B2, 40, 00, 9C, 8F, 05, 00, B3, 40, 00, 8B, 45, 00, A3, F4, B2, 40, 00, 8B, 45, 04, A3, F8, B2, 40, 00, 8D, 45, 08, A3, 04, B3, 40...
 
[+]

Code size:
28 KB (28,672 bytes)

Service
Display name:
MYSecurityCenter Update Service

Service name:
UPDATESRV

Description:
Downloads MYSecurityCenter updates and new malware signatures from the Internet.

Type:
Win32OwnProcess


Remove updatesrv.exe - Powered by Reason Core Security