pokkiInstaller.exe

Pokki Installer

GTE Corporation

The application pokkiInstaller.exe by GTE has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Pokki  (signed by GTE Corporation)

Product:
Pokki Installer

Version:
0.269.8.116

MD5:
ffd960867c44b52f90afe6612e2150b4

SHA-1:
6e712fddd53e24643364a68faa731ccb7e0ab03f

SHA-256:
38b23c78449cae9f6e317baee14bfa68107edbf83dcbdd72f856ae2bb8779f6c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 6:18:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Pokki (L)
17.3.12.4

File size:
2.8 MB (2,959,664 bytes)

Product version:
0.269.8.116

Copyright:
Copyright (C) 2010-2014 - SweetLabs, Inc

Original file name:
pokkiInstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\pokkiinstaller.exe

Digital Signature
Signed by:

Authority:
GTE Corporation

Valid from:
8/13/1998 4:59:00 AM

Valid to:
8/14/2018 4:29:00 AM

Subject:
CN=GTE CyberTrust Global Root, OU="GTE CyberTrust Solutions, Inc.", O=GTE Corporation, C=US

Issuer:
CN=GTE CyberTrust Global Root, OU="GTE CyberTrust Solutions, Inc.", O=GTE Corporation, C=US

Serial number:
01A5

File PE Metadata
Compilation timestamp:
11/23/2016 1:38:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x13B8F2

Entry point:
60, C1, F9, EF, 89, D5, 80, F6, EC, 0F, AD, E9, 88, D6, 2D, 55, 24, 58, 24, F2, 0F, AC, E8, 2D, 0F, AB, CD, 0F, AD, EF, 81, F9, E2, 9B, 00, 00, 69, D3, 2C, B6, 85, 50, 81, E0, 3A, 48, 23, 59, 89, CB, 4E, 0F, BF, FD, 45, C7, C5, C1, 68, 5C, BE, 68, BA, A7, 01, 00, BA, FB, 5D, E1, 8D, C7, C6, F6, 22, 99, EF, E8, 19, 00, 00, 00, 89, F7, 0F, C0, ED, 33, DF, C7, C5, 4B, C2, A8, 5C, 0F, BA, FE, 00, 81, F2, EB, 15, 00, 00, D0, F4, 0F, A3, D2, 69, DD, 0C, 06, E5, 79, 0F, CB, FE, CF, 0F, B7, C1, 8D, 0D, 69, E1, 64...
 
[+]

Entropy:
7.0748

Code size:
1.5 MB (1,563,648 bytes)

Remove pokkiInstaller.exe - Powered by Reason Core Security