Launcher.exe

Game Launcher

This is a setup program which is used to install the application. This is the uninstaller utility registered in the Windows Control Panel for the program Argen Live Poker. The file has been seen being downloaded from www.argenlivepoker.com.
Product:
Game Launcher

Version:
3.10.0.14359

MD5:
76d160c87eec8266a033f29b5d0addc0

SHA-1:
17a5fdf99fbf0720b33a388d74309bf6e13ffc4b

SHA-256:
047681647cb217ec304b6d695b0f11c7255767efb10a540206616a0c07ef1f30

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/25/2024 4:28:12 PM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
W32/Ramnit.C
7.11.30.172

File size:
648.5 KB (664,064 bytes)

Product version:
3.10.0.14359

Copyright:
Copyright (C) 2007-2016

Original file name:
Launcher.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\argen live poker\launcher.exe

File PE Metadata
Compilation timestamp:
1/21/2016 10:33:27 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:OdcjbSQPBAfsp300bG+VabVAXsBRicfIvghBaZy+aP3zImYB2eSdGUMi:ayRCq0MXeAcwhZyxDYAe3i

Entry address:
0x1E41A0

Entry point:
60, BE, 00, 80, 55, 00, 8D, BE, 00, 90, EA, FF, 57, EB, 0B, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07, 8B...
 
[+]

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.24

Code size:
564 KB (577,536 bytes)

Program Uninstaller
Program name:
Argen Live Poker

Uninstall string:
"C:\Program Files\argen live poker\launcher.exe" \uninstall "C:\users\{user}\desktop\argen live poker.lnk"


The file Launcher.exe has been seen being distributed by the following URL.

Scan Launcher.exe - Powered by Reason Core Security