LiveUpdate.exe

System Cleaner

Pointstone Software, LLC

The application LiveUpdate.exe by Pointstone Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program System Cleaner 7 by Pointstone Software, LLC. While running, it connects to the Internet address pointstone.com on port 80 using the HTTP protocol.
Publisher:
Pointstone Software, LLC  (signed and verified)

Product:
System Cleaner

Description:
Live Update

Version:
6.0.0.0

MD5:
6a56f598b6f82d601316ed1c4fc64fda

SHA-1:
d4ede3ca7fc918ee3bb8af640803f924ae8970e4

SHA-256:
5dd8ac76e385830b1dc041e07a3b776c8e8425aea546518c3695ca54736df7c7

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/27/2024 4:22:59 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Pointstone
15.7.29.3

File size:
217.6 KB (222,816 bytes)

Copyright:
Copyright © 1997 - 2013 Pointstone Software, LLC. All rights reserved.

Trademarks:
System Cleaner is a registered trademark of Pointstone Software, LLC. (United States Patent and Trademark Office registration number 2926385)

Original file name:
LiveUpdate.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pointstone\system cleaner 7\liveupdate.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/18/2012 8:00:00 PM

Valid to:
3/19/2014 7:59:59 PM

Subject:
CN="Pointstone Software, LLC", O="Pointstone Software, LLC", STREET="2915 Ogletown Road, #342", L=Newark, S=DE, PostalCode=19713, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6A22BB97E19FF5ADFB20EE6464F9DEFA

File PE Metadata
Compilation timestamp:
7/5/2013 2:12:09 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
3072:N92ZacUSzSQuovQHMxtvq2sqYak06+gk99F9G5usVUY47/1n:N92ZaZSOQvQHMCnak06+gk99vG5u+I

Entry address:
0xD4A0

Entry point:
55, 8B, EC, B9, 04, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 51, B8, 60, BA, 40, 00, E8, 3E, 3D, FF, FF, 33, C0, 55, 68, EF, D5, 40, 00, 64, FF, 30, 64, 89, 20, A1, 00, 1A, 41, 00, 8B, 00, E8, B4, 4C, FF, FF, A1, 00, 1A, 41, 00, 8B, 00, B2, 01, E8, CE, 4C, FF, FF, A1, 00, 1A, 41, 00, 8B, 00, BA, 08, D6, 40, 00, E8, 85, 4C, FF, FF, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 00, 3B, FF, FF, 83, 7D, EC, 00, 0F, 84, A6, 00, 00, 00, 8D, 55, E8, B8, 01, 00, 00, 00, E8, E9, 3A, FF, FF, 8B, 45, E8, BA, 2C, D6, 40, 00, E8...
 
[+]

Entropy:
6.8301

Developed / compiled with:
Microsoft Visual C++

Code size:
48 KB (49,152 bytes)

The file LiveUpdate.exe has been discovered within the following program.

System Cleaner 7  by Pointstone Software, LLC
Publisher's description - “Fix your PC's problems, and help prevent them from recurring with System Cleaner's suite of maintenance tools. System Cleaner restores your PC's performance, frees up wasted disk space, prevents registry corruption and protects your online privacy. Your PC is slowing down.”
www.systemcleaner.com
45% remove it
 
Powered by Should I Remove It?

The executing file has been seen to make the following network communication in live environments.

TCP (HTTP):
Connects to pointstone.com  (108.61.26.20:80)

Remove LiveUpdate.exe - Powered by Reason Core Security