Launcher.exe

Metin2 AutoPatcher

Dupl3xx

This is a setup program which is used to install the application. The file has been seen being downloaded from dstats.net and multiple other hosts.
Publisher:
Dupl3xx

Product:
Metin2 AutoPatcher

Version:
1.0.0.1

MD5:
4a0806cfe23ff0de598701ba3c33f046

SHA-1:
53a622170dd7eadccddf338acf185ec66e175fda

SHA-256:
18421f16c2e1b18a4a8b107f427df58bafeedd151adecf13a5a4fd3cce572876

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/27/2024 11:45:23 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Baidu Antivirus
Adware.Win32.Agent
4.0.3.151027

Zillya! Antivirus
Adware.MultiPlug.Win32.498818
2.0.0.2477

File size:
1 MB (1,064,960 bytes)

Product version:
1.0.0.1

Copyright:
Copyright © QuadCore.cz 2011

Original file name:
Launcher.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\quadcorem2\launcher.exe

File PE Metadata
Compilation timestamp:
4/18/2015 6:16:32 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:Qp1xSRpsSvaJ8mgwswLGXEyyi26+Q6yi26+Q76Jp1xSRpsSvaJ8m:vsSvaJ8mgN8G0nlYlGxsSvaJ8m

Entry address:
0xAEBEE

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, A0, DA, 31, 55, 00, 00, 00, 00, 02, 00, 00, 00, 54, 00, 00, 00, 1C, 00, 0B, 00, 1C, D0, 0A, 00, 52, 53, 44, 53, 58, AA, BA, 67, C9, EE, 8D, 4C, 8B, A8, 54, 5C, 5F, B9, 57, F4, 01, 00, 00, 00, 44, 3A, 5C, 53, 65, 72, 76, 65, 72, 5C, 6B, 6C, 69, 65, 6E, 74, 5C, 61, 5C, 4D, 65, 74, 69, 6E, 32, 5F, 50, 61, 74, 63, 68, 65, 72, 5F, 58, 50, 5C, 6F, 62, 6A, 5C, 44, 65, 62, 75, 67, 5C, 4C, 61, 75, 6E, 63, 68, 65, 72, 2E, 70, 64...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
691 KB (707,584 bytes)

The file Launcher.exe has been seen being distributed by the following 2 URLs.

http://dstats.net/download/http://.../Launcher.exe

Scan Launcher.exe - Powered by Reason Core Security