lefttoeupdate.exe

Sice Xing

The application lefttoeupdate.exe by Sice Xing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a Windows kernel mode device driver named “Update Service(LefttoeU)”.
Publisher:
Sice Xing  (signed and verified)

MD5:
475bdfa27b398232312c479ac6289067

SHA-1:
dc2405622e0692e7cf602b59afa8e22c1046ce91

SHA-256:
111af84fcc315ec55ecea49d456e2ab78129750cd9e155e535c06bc5a9581500

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
1/11/2025 12:11:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
17.2.16.8

File size:
576.4 KB (590,208 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\lefttoe\update\lefttoeupdate.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/29/2016 5:30:00 AM

Valid to:
4/2/2017 5:29:59 AM

Subject:
CN=Sice Xing, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
42718540F3923EE935B3B6F533A8F377

File PE Metadata
Compilation timestamp:
6/30/2016 8:09:53 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

Entry address:
0x4D8AB

Entry point:
A3, F3, 4E, 00, 00, A2, CB, B5, B4, B4, B4, 6E, A3, 58, 0C, 00, C0, 06, BF, 2F, C2, 46, 00, 00, 00, 00, 12, 14, 14, 15, 10, C0, AE, 16, 1A, B9, 88, 1B, 2F, B4, 7E, 00, 00, 00, 00, C6, 0F, 6F, 47, 60, 2F, 6F, 47, 18, 1D, 1C, C2, 63, C0, A3, EA, F7, EA, 03, 00, 78, 8E, 1B, B4, 3E, B7, 8C, 0E, B7, B4, B4, B4, B4, C6, 0E, BF, 2F, E8, 00, 00, 00, 00, B9, 88, 1B, 2F, B4, 7E, 00, 00, 00, 00, C6, 0F, 6F, 47, 60, 2F, 6F, 47, 18, 1D, 1C, C2, 63, C0, A3, EA, F7, EA, 03, 00, 78, 8E, 1B, C2, 2E, BB, B4, 3E, B7, 8C, 0E...
 
[+]

Entropy:
6.4662

Code size:
445.5 KB (456,192 bytes)

Driver
Display name:
Update Service(LefttoeU)

Service name:
LefttoeU

Description:
Keeps your Lefttoe software up to date. If this service is disabled or stopped, your Lefttoe software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and f

Type:
Kernel device driver (KernelDriver)

Depends on:
RpcSs


Remove lefttoeupdate.exe - Powered by Reason Core Security