import_root_cert.exe

LLC

The application import_root_cert.exe by LLC has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
LLC   (signed and verified)

MD5:
3b1ba0ecfd31d9ee83776889f5b15125

SHA-1:
5e6968d654810ac86bbb1cab89c04cac11036241

SHA-256:
36bd1b94118fb59e7d65119f91819b647e801396dc033908f633270ec94a4bb5

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 5:31:53 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Amonitize
16.12.24.6

File size:
97.3 KB (99,584 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\ProgramData\contentprotector\win32\import_root_cert.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
2/14/2016 3:00:00 AM

Valid to:
2/14/2017 2:59:59 AM

Subject:
CN="LLC ""TIMARKO IT""", OU=IT, O="LLC ""TIMARKO IT""", STREET="Vulytsya Lenina, Budynok 33, Korpus A, Ofis", L=Berezanka, S=Mykolayivska, PostalCode=57400, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00AAE91A6E10A17EB04E7058AC5F3C8447

File PE Metadata
Compilation timestamp:
8/3/2012 2:25:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x54EA

Entry point:
5E, 4C, 45, 6B, 04, 4C, 11, FF, 71, 69, 45, B5, A0, B6, 4C, 8E, 62, 52, D4, 0A, B1, A8, 53, 82, 3A, C4, 87, AF, 0C, 73, 1B, 6F, E7, 6C, 98, C1, BC, D9, DA, 61, B5, CD, 47, 90, F4, B8, 27, 6B, 44, 6D, 95, 58, F1, 1C, FB, 67, 41, 40, F9, 8F, FE, 24, 25, 95, 21, F6, 67, 9A, 8B, 39, F0, 61, 68, CE, 99, 52, 3E, 38, AB, 2F, 1F, 9F, 88, AB, EC, 04, F1, B8, 34, EC, 17, A9, B1, 5D, AC, 9B, 2A, 5E, 49, 02, 25, 71, 0F, C0, 4B, 1A, 1D, 17, 29, 9A, 2E, 1C, C0, CC, 89, E4, 93, 8C, 36, 18, F6, 7D, 77, 67, F8, BC, B9, 81...
 
[+]

Code size:
60 KB (61,440 bytes)

Remove import_root_cert.exe - Powered by Reason Core Security