chromeextinstaller.exe

RAFO TECHNOLOGY INC

The application chromeextinstaller.exe by RAFO TECHNOLOGY INC has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
RAFO TECHNOLOGY INC  (signed and verified)

MD5:
a28e6dadcc086bfed6dcb149ad500758

SHA-1:
11ffbcb047485fd47a68222d1f7d4390026ccba3

SHA-256:
98427ac819adaa5f23065cc82b074067e130b09c29ce8677dbcfb917e97f5c5b

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/26/2024 11:12:11 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.RafoTech (M)
16.11.15.13

File size:
183.2 KB (187,576 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\dealwifi\chromeextinstaller.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/27/2016 7:07:34 AM

Valid to:
4/18/2019 6:50:02 AM

Subject:
CN=RAFO TECHNOLOGY INC, O=RAFO TECHNOLOGY INC, L=Alhambra, S=California, C=US

Issuer:
CN=GlobalSign CodeSigning CA - G3, O=GlobalSign nv-sa, C=BE

Serial number:
3F088EAB1E0AD5AF37C04EFB

File PE Metadata
Compilation timestamp:
7/28/2016 9:32:52 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:q0xKZju5nIvsV9ty1Pt2/YN5cCcxB0FXhh8x6B0F7cqLDPvvDMM0TBf1Y5Xcl67Y:dV9o4/+VS58TBtY5Xw67ub

Entry address:
0x1B26A

Entry point:
E8, 62, 02, 00, 00, E9, 49, FE, FF, FF, FF, 25, 80, E2, 41, 00, FF, 25, 84, E2, 41, 00, FF, 25, 8C, E2, 41, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 68, E9, B2, 41, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 00, C0, 42, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, 55...
 
[+]

Entropy:
6.5481

Code size:
114 KB (116,736 bytes)

Remove chromeextinstaller.exe - Powered by Reason Core Security