update.exe

update

The executable update.exe has been detected as malware by 8 anti-virus scanners.
Product:
update

Version:
2, 0, 0, 7

MD5:
7962ecefa62237f609292ce9a0688b93

SHA-1:
bdf3db3a88825be265f5d8a86a57d9a3fd010d8a

SHA-256:
515f5188ba6d039b8c38f60d3d868fa9c9726e144f593066490c7c97bf5090c8

Scanner detections:
8 / 68

Status:
Malware

Analysis date:
4/28/2024 7:29:31 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Trojan.Agent
7.1.1

Comodo Security
UnclassifiedMalware
16801

Norman
Troj_Generic.DSGCP
11.20140402

Quick Heal
Trojan.Agent.tlyi
4.14.12.00

Trend Micro House Call
TROJ_GEN.RCBH1LN
7.2.92

Vba32 AntiVirus
TrojanDropper.MSIL.Agent
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20730

ViRobot
Trojan.Win32.A.Agent.339456.A
2011.4.7.4223

File size:
276 KB (282,624 bytes)

Product version:
2, 0, 0, 7

Copyright:
Copyright (C) 2012

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\ProgramData\mcafee\common framework\current\vse88int2007\install\0000\update.exe

File PE Metadata
Compilation timestamp:
3/8/2012 10:59:48 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
6144:57v2qpIYih+xyrQrVmdzBlZlKLcmPm93nskQEX+VJfAnmU4K:573yWmdzBlZlK/PmdskVQAnz4K

Entry address:
0x17C69

Entry point:
E8, 72, 37, 00, 00, E9, 79, FE, FF, FF, 3B, 0D, DC, 6D, 43, 00, 75, 02, F3, C3, E9, F4, 37, 00, 00, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 57, 33, FF, 3B, F7, 75, 04, 33, C0, EB, 65, 39, 7D, 08, 75, 1B, E8, 38, 18, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 6D, 3D, 00, 00, 83, C4, 14, 8B, C6, EB, 45, 39, 7D, 10, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, B4, 38, 00, 00, 83, C4, 0C, EB, C1, FF, 75, 0C, 57, FF, 75, 08, E8, 73, 18, 00, 00, 83, C4, 0C, 39, 7D, 10, 74, B6, 39, 75, 0C, 73...
 
[+]

Entropy:
6.4145

Code size:
165 KB (168,960 bytes)

Remove update.exe - Powered by Reason Core Security