eUpgrade.exe

Elex Upgrade

Taiwan Shui Mu Chih Ching Technology Limited

The application eUpgrade.exe, “Elex Upgrade Application” by Taiwan Shui Mu Chih Ching Technology Limited has been detected as adware by 3 anti-malware scanners. It is also typically executed from the user's temporary directory.
Publisher:
Taiwan Shui Mu Chih Ching Technology Limited.  (signed by Taiwan Shui Mu Chih Ching Technology Limited)

Product:
Elex Upgrade

Description:
Elex Upgrade Application

Version:
1.5.90.8812

MD5:
9295a05fd4be08adce78c6003d89cd7c

SHA-1:
859d9a00fd35d25a6aab89dd4dde57d0e7ec75ee

SHA-256:
8fa579b09973dd4ac5b1c553335908cff895230faa2b316e32b81a24f97ee4ef

Scanner detections:
3 / 68

Status:
Adware

Analysis date:
11/4/2024 5:09:20 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Mutabaha.229
9.0.1.05190

ESET NOD32
Win32/ELEX.BU potentially unwanted application
7.0.302.0

Reason Heuristics
PUP.Thinknice.TaiwanSh (M)
16.5.7.14

File size:
1.3 MB (1,365,504 bytes)

Product version:
1.5.90.8812

Copyright:
Copyright (c) 2011-2015 Taiwan Shui Mu Chih Ching Technology Limited.

Original file name:
eUpgrade.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ste330.tmp\eupgrade\eupgrade.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/4/2015 9:26:37 AM

Valid to:
3/4/2016 9:26:37 AM

Subject:
CN=Taiwan Shui Mu Chih Ching Technology Limited, O=Taiwan Shui Mu Chih Ching Technology Limited, L=Taipei City, S=Taiwan, C=TW

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121003857AB2AD439A7293EF2F1A8B3DCB6

File PE Metadata
Compilation timestamp:
3/5/2015 6:36:42 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:ofE69B92sb9SHR2+FJcy6b87TbSzTKjserUy:ofX7456buTbSzOJ

Entry address:
0xA0442

Entry point:
E8, 96, 6F, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8D, 45, 14, 50, 6A, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, AD, 7E, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 83, 7D, 08, 00, 74, 2D, FF, 75, 08, 6A, 00, FF, 35, D4, F8, 50, 00, FF, 15, 40, B1, 4C, 00, 85, C0, 75, 18, 56, E8, 47, 2F, 00, 00, 8B, F0, FF, 15, 9C, B2, 4C, 00, 50, E8, F7, 2E, 00, 00, 59, 89, 06, 5E, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 4D, 0C, 53, 33, DB, 3B, CB, 76, 1B, 6A, E0, 33, D2, 58, F7, F1, 3B, 45, 10, 73, 0F, E8, 13, 2F...
 
[+]

Code size:
805.5 KB (824,832 bytes)

Remove eUpgrade.exe - Powered by Reason Core Security