mpkview.exe

Mipko OOO

The application mpkview.exe by Mipko OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Mipko OOO  (signed and verified)

Description:
MIPKO Software

Version:
7.2.1.1445

MD5:
a2039385064ed816776aeeb80c152fc9

SHA-1:
20a268156f1068c56ca7f44ddc03fafd7b19fe16

SHA-256:
729de7e7973ca6c8e92e811fe8e935eb79255febed5d3c738a96ae899ff971bb

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/24/2024 9:41:44 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Mipko (M)
16.6.18.17

File size:
3.8 MB (3,957,064 bytes)

Product version:
7.2.1.1445

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\mpk\mpkview.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/25/2010 2:00:00 AM

Valid to:
11/25/2012 1:59:59 AM

Subject:
CN=Mipko OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Mipko OOO, L=Pskov, S=Pskov, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
744A4A940AA3FE09F15CC2879605C21D

File PE Metadata
Compilation timestamp:
2/13/2012 9:47:36 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:ebgfpicqyEPViNZ3xR4HDuG4v0Bq5SvQBGxYJq+:ebkFGVuxoSG4stQBA1+

Entry address:
0x1000

Entry point:
68, 01, 50, C4, 00, E8, 01, 00, 00, 00, C3, C3, 7D, 08, 30, 14, A3, 65, 64, C9, A5, 9C, 70, BA, CE, D2, 85, 83, D9, 88, B6, 20, CC, 1A, 69, 8B, FF, 67, 29, 81, D1, 9C, 47, E1, 59, 83, D3, 10, 60, 49, D7, E0, 34, 0A, E8, C5, 26, B2, A7, E1, C9, 82, 92, 1D, 75, 05, 7C, 00, C2, E5, B2, 0C, BF, 8A, 44, 65, 7A, DE, E9, D3, 3E, E2, 37, F8, 70, 48, CB, 95, DC, 44, 19, 8A, 48, E5, 7A, 92, D1, 24, BD, D8, E0, 0D, 5C, DF, ED, C9, DE, 47, A1, 63, 2A, E6, 5F, 8F, 80, 2F, E2, 81, 5A, 95, 9D, 3B, 67, AA, 67, 68, 03, 11...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
4.8 MB (5,068,800 bytes)

Windows Firewall Allowed Program
Name:
tcp\ip


Remove mpkview.exe - Powered by Reason Core Security