vmprotect_lm.exe

VMProtect License Manager

Ivan Yurievich Permyakov IP

The application vmprotect_lm.exe by Ivan Yurievich Permyakov IP has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
VMProtect Software  (signed by Ivan Yurievich Permyakov IP)

Product:
VMProtect License Manager

Version:
2.0.5.0

MD5:
9414f7907ff40cac112f86df9fadf167

SHA-1:
37f568c43cd87fa54f830e070ce9f488ac8d6af7

SHA-256:
3d5d9a9d7a65ef1982be17bf841a5895f74a18ed6fefc5b41e2ad39cf93a1349

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/30/2024 11:19:02 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.IvanYuri (M)
16.7.8.4

File size:
1.2 MB (1,239,816 bytes)

Product version:
2.0.5.0

Copyright:
(c) 2003-2010 VMProtect Software. All rights reserved.

Original file name:
VMProtect License Manager.exe

File type:
Executable application (Win32 EXE)

Digital Signature
Authority:
The USERTRUST Network

Valid from:
4/14/2010 8:00:00 AM

Valid to:
4/15/2011 7:59:59 AM

Subject:
CN=Ivan Yurievich Permyakov IP, O=Ivan Yurievich Permyakov IP, STREET=Uktusskaya ul. 47 office 54, L=Ekaterinburg, S=Sverdlovskaya obl., PostalCode=620144, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
01778B48596E33363F7FB6ECF530E841

File PE Metadata
Compilation timestamp:
5/15/2010 10:35:18 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:yNDDsgvasqenAzl/QQdsvaAyra2alS8x6W6+NhmE+1+6zV/LR:EDDnvHIl/QQaGa2as8oaNhmw6zVF

Entry address:
0x2A33BF

Entry point:
53, 9C, 9C, E8, 6A, 68, FF, FF, 0B, 46, 0F, BF, D0, 94, F7, 44, FB, 78, CF, 08, B3, 78, AB, A8, AB, 61, B6, EB, 07, B4, 49, A9, ED, 72, 71, 3C, 6F, 58, E9, 68, C5, 5A, 90, 3B, B0, EB, D4, 33, 90, 2F, 63, 9D, 13, FB, 3B, E3, 79, AE, 92, 25, 9D, 8B, C1, 5E, 7D, AB, 72, CA, FE, 3C, EB, D9, 5B, 9E, 05, DE, 09, A1, F2, 28, 83, B5, 14, 96, 4A, C9, 61, BA, 65, 38, 5F, 23, 9E, 7E, 32, B6, 47, 26, 4B, 80, D6, 35, C5, CA, 10, 93, 99, 69, 9A, 41, AB, 1C, F4, 77, 7B, F8, 77, D8, 03, 9B, C8, 0B, 5D, 69, AB, 00, 4D, C3...
 
[+]

Entropy:
7.9673  (probably packed)

Code size:
3.6 MB (3,767,296 bytes)

Remove vmprotect_lm.exe - Powered by Reason Core Security