UpdateWindow.exe

UpdateWindow

SmartCrew Co.,Ltd

The application UpdateWindow.exe by SmartCrew Co.,Ltd has been detected as a potentially unwanted program by 18 anti-malware scanners.
Publisher:
SmartCrew Co.,Ltd  (signed and verified)

Product:
UpdateWindow

Description:
down_client

Version:
2, 1, 2, 1

MD5:
d29fc567ee427931049c6f16401d337c

SHA-1:
5cae08c0c4d3ea1d7d5dcaea2044bc9b70aeda62

SHA-256:
f36958a2be906009d4ed0a1375b8a0cf2304947272951dd92a42c99a189fcc51

Scanner detections:
18 / 68

Status:
Potentially unwanted

Analysis date:
4/18/2024 5:10:53 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Kraddare
7.1.1

Avira AntiVirus
TR/Graftor.Elzob.6053.14
7.11.140.88

Bitdefender
Gen:Variant.Graftor.Elzob.6053
1.0.20.670

Comodo Security
ApplicUnwnt
18025

Emsisoft Anti-Malware
Gen:Variant.Graftor.Elzob.6053
8.14.05.14.05

ESET NOD32
Win32/Adware.Kraddare.FM (variant)
8.9617

Fortinet FortiGate
Riskware/Kraddare
5/14/2014

F-Secure
Gen:Variant.Graftor.Elzob.6053
11.2014-14-05_4

G Data
Gen:Variant.Graftor.Elzob.6053
14.5.24

K7 AntiVirus
Unwanted-Program
13.176.11613

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.3869

McAfee
Artemis!D29FC567EE42
5600.7131

MicroWorld eScan
Gen:Variant.Graftor.Elzob.6053
15.0.0.402

nProtect
Adware/W32.Agent.272680
14.03.31.01

Sophos
Generic PUA FM
4.98

Trend Micro House Call
ADW_KRADDARE
7.2.134

Trend Micro
ADW_KRADDARE
10.465.14

VIPRE Antivirus
Trojan.Win32.Generic
27892

File size:
266.3 KB (272,680 bytes)

Product version:
2, 1, 2, 1

Copyright:
Copyright (c) - 2012

Original file name:
UpdateWindow.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\temporary internet files\content.ie5\{random}\updatewindow.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
10/23/2013 2:00:00 AM

Valid to:
10/24/2014 1:59:59 AM

Subject:
CN="SmartCrew Co.,Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="SmartCrew Co.,Ltd", L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
36B2F93EF0896C93C856C97B615FBA26

File PE Metadata
Compilation timestamp:
10/30/2013 3:47:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:u8nVqLESVjHA7v2uI7ALOFF5UDMVyKvP9i79IwOk:urjHHuI7ATwP9UKk

Entry address:
0x15CDC

Entry point:
E8, 1C, A0, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, 60, F7, 42, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 85, C0, 5F, 89, 45, FC, 5E, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, C4, D0, 42, 00, C9, C2, 08, 00, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B...
 
[+]

Entropy:
6.2551

Code size:
176 KB (180,224 bytes)

Remove UpdateWindow.exe - Powered by Reason Core Security