ClickOnceSetup.exe

Web

Contas Premium Servicos LTDA

The application ClickOnceSetup.exe by Contas Premium ServicosA has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a self-extracting archive and installer and has been known to bundle potentially unwanted software.
Publisher:
Contas Premium Servicos LTDA  (signed and verified)

Product:
Web

Version:
3.8.7

MD5:
ca4c19307cdeb2d27b9bc9053604a9b6

SHA-1:
ff4022e374374128bcd60c1bd9b0ce0fe156e645

SHA-256:
277128f8c587d73d0edf6807fb275a33dc567ea3d8a177374164dfb32948cad6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/28/2024 12:18:13 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.installCore (M)
17.2.9.10

File size:
982.9 KB (1,006,528 bytes)

Product version:
3.8.7

Original file name:
ClickOnceSetup.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\apps\2.0\dqo707ra.lgm\og23whgh.0y1\clic..tion_0000000000000000_0001.0000_7e107d187a70be62\clickoncesetup.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
10/13/2014 7:12:04 AM

Valid to:
10/14/2015 7:12:04 AM

Subject:
CN=Contas Premium Servicos LTDA, O=Contas Premium Servicos LTDA, L=Maceio, S=Alagoas, C=BR

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121123E475FA55B5D738E3D6E0303FE7EAD

File PE Metadata
Compilation timestamp:
8/16/2015 5:39:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

Entry address:
0xEDE3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
944 KB (966,656 bytes)

Remove ClickOnceSetup.exe - Powered by Reason Core Security