mailruhomesearch.exe

Astonsoft DeepBurner

MALITEK

The application mailruhomesearch.exe by MALITEK has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘mailruhomesearch’.
Publisher:
Astonsoft  (signed by MALITEK)

Product:
Astonsoft DeepBurner

Version:
1.9.0.228

MD5:
10b5dd2808c641d277b4d08380fe548d

SHA-1:
30b0ebf137aa19f91c158d9f8bf401e4dfa96a02

SHA-256:
517c43ffcd425e6cc83df08bae54dd67a026ca77f9f689d284f29349f44ba420

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 5:15:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.InstallMonster (M)
17.2.28.12

File size:
2.7 MB (2,856,888 bytes)

Product version:
1.8

Copyright:
Astonsoft (c) 2002 - 2006

Original file name:
DeepBurner.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\mail.ru\sputnik\ptls\mailruhomesearch.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
3/12/2016 2:00:00 AM

Valid to:
3/13/2017 1:59:59 AM

Subject:
CN=MALITEK, O=MALITEK, STREET="Gazovikov, 30, 160", L=Tyumen, S=RU, PostalCode=625022, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EE626B9BCE0A4EB8C590A5CF0E187D8D

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

Entry address:
0x76D000

Entry point:
FC, 49, B8, A4, CF, B6, 00, 83, C0, 70, 50, C3, C2, 08, 00, B9, 20, 10, 00, 00, B8, 01, 00, 00, 00, 8B, 90, 98, A3, B6, 00, 0F, B6, 12, 80, EA, B1, 83, EA, 07, 0B, D2, 75, 20, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, 09, A9, 09, E8, E9, F5, 06, 00, 00, DA, 81, E9, DB, E3, AC, 00, E9, A3, 06, 00, 00, 98, 15, 97, 51, EB, 14, 6F, DC, B8, 9D, EB, 03, 9C, EB, 01, C3, 81, 6C, 24, 04, 28, 10, A4, A0, EB, EF, 68, 7B, E7, 5A, A1, EB, EB, EE, 2D...
 
[+]

Entropy:
7.8969  (probably packed)

Code size:
648.5 KB (664,064 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
mailruhomesearch

Command:
"C:\users\{user}\appdata\local\mail.ru\sputnik\ptls\mailruhomesearch.exe" --pr_deferred


Remove mailruhomesearch.exe - Powered by Reason Core Security