upgrade.exe

ccUpgrade

Total Defense, Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ISSUpgrade’.
Publisher:
Total Defense, Inc.  (signed and verified)

Product:
ccUpgrade

Version:
9.0.0.394

MD5:
2ae034c3215192be65f9eea96dc4acc5

SHA-1:
81ed64f03df452416b19782ba9f4da47b9d2d595

SHA-256:
a0d3fab38c3eff4c137307bb1fb3f9f2e2ca3b7672ae135adf38c56084d145b4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 4:11:21 PM UTC  (today)

File size:
580.1 KB (594,072 bytes)

Product version:
9.0.0.394

Copyright:
Copyright(C) 2015 Total Defense, Inc. All rights reserved

Original file name:
ccUpgrade.exe

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\Program Files\common files\av\avplus\upgrade.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
9/17/2014 7:00:00 PM

Valid to:
9/22/2015 7:00:00 AM

Subject:
CN="Total Defense, Inc.", O="Total Defense, Inc.", L=Hauppauge, S=New York, C=US

Issuer:
CN=DigiCert Assured ID Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0FAA7FA038F97D3CA058B235FFBD9A95

File PE Metadata
Compilation timestamp:
8/6/2015 4:25:47 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:o0tuuCBO7cNz1ja1ZEsIdV0RooCSmpmMBwdXpwi8SjRm7Gt:TTCBN1jOZ2dV06fpmMBwd538ImSt

Entry address:
0x4900C

Entry point:
E8, 73, DB, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 18, 53, 56, 57, 33, DB, 6A, 01, 53, 53, FF, 75, 08, 89, 5D, F0, 89, 5D, F4, E8, 60, C1, 00, 00, 89, 45, E8, 23, C2, 83, C4, 10, 83, F8, FF, 89, 55, EC, 74, 59, 6A, 02, 53, 53, FF, 75, 08, E8, 44, C1, 00, 00, 8B, C8, 23, CA, 83, C4, 10, 83, F9, FF, 74, 41, 8B, 75, 0C, 8B, 7D, 10, 2B, F0, 1B, FA, 0F, 88, C6, 00, 00, 00, 7F, 08, 3B, F3, 0F, 86, BC, 00, 00, 00, BB, 00, 10, 00, 00, 53, 6A, 08, FF, 15, D0, E0, 46, 00, 50, FF, 15, CC, E0, 46, 00, 85, C0...
 
[+]

Entropy:
6.3396

Code size:
436 KB (446,464 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ISSUpgrade

Command:
"C:\Program Files\common files\av\avplus\upgrade.exe"


Scan upgrade.exe - Powered by Reason Core Security