yesdearupdate.exe

Sice Xing

The application yesdearupdate.exe by Sice Xing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Update Service(YesdearU)”. It runs as a scheduled task under the Windows Task Scheduler named YesdearUpdateTaskMachineCore triggered by a time event.
Publisher:
Sice Xing  (signed and verified)

MD5:
96271e4a05e4f50e6539db45aad2cc88

SHA-1:
498ea13288122b8bc2a31c5882a3b11c2523aed8

SHA-256:
2611c214492ad640a92dcc6636d00e4840319c9f7ed26cfccdf54131e342598d

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/17/2025 6:21:15 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex.SiceXing (M)
16.7.14.15

File size:
552.9 KB (566,144 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\yesdear\update\yesdearupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
7/8/2016 3:00:00 AM

Valid to:
4/2/2017 2:59:59 AM

Subject:
CN=Sice Xing, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
62EEAD6B43E8FB7276E133CA2A5B42EF

File PE Metadata
Compilation timestamp:
7/8/2016 10:46:30 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:gJJEXJKavL7uVRaQUtDS0Xq8rJvzQGuNSsHWg:IJEXQavL7+cQjUqMkXMsHWg

Entry address:
0x48DBD

Entry point:
82, DC, 6F, 00, 00, 83, EA, 94, 95, 95, 95, 4F, B2, A9, 2C, 00, E1, 27, 9E, 0E, E3, 67, 00, 00, 00, 00, 33, 35, 35, 34, 31, E1, 8F, 37, 3B, 98, A9, 3A, 0E, 95, 5F, 00, 00, 00, 00, E7, 2E, 4E, 66, 41, 0E, 4E, 66, 39, 3C, 3D, E3, 42, E1, 82, CB, D6, 3B, 22, 00, 59, AF, 3A, 95, 1F, 96, AD, 2F, 96, 95, 95, 95, 95, E7, 2F, 9E, 0E, C9, 00, 00, 00, 00, 98, A9, 3A, 0E, 95, 5F, 00, 00, 00, 00, E7, 2E, 4E, 66, 41, 0E, 4E, 66, 39, 3C, 3D, E3, 42, E1, 82, CB, D6, 3B, 22, 00, 59, AF, 3A, E3, 0F, 9A, 95, 1F, 96, AD, 2F...
 
[+]

Entropy:
6.4573

Code size:
424.5 KB (434,688 bytes)

Scheduled Task
Task name:
YesdearUpdateTaskMachineCore

Trigger:
Time


Service
Display name:
Update Service(YesdearU)

Service name:
YesdearU

Description:
Keeps your Yesdear software up to date. If this service is disabled or stopped, your Yesdear software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and f

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove yesdearupdate.exe - Powered by Reason Core Security