ptu4fd_tmp.exe

Playtech Limited

The application ptu4fd_tmp.exe by Playtech Limited has been detected as a potentially unwanted program by 9 anti-malware scanners.
Publisher:
Playtech Limited  (signed and verified)

MD5:
741d5a869c3611fec1426ff6ca618402

SHA-1:
3e1ae1c04a79d2d7593f38a221979abecdfe2e8f

Scanner detections:
9 / 68

Status:
Potentially unwanted

Analysis date:
11/24/2024 7:32:27 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/PTCasino (variant)
9.4073

Fortinet FortiGate
Misc/CasOnline
1/30/2015

F-Prot
W32/Casino.D.gen
v6.4.4.4.56

K7 AntiVirus
Trojan.Win32.Malware.4
13.7.10.734

McAfee
potentially unwanted program CasOnline
5600.6870

Prevx
High Risk Worm
3.0

Quick Heal
(Suspicious) - DNAScan
1.15.10.00

Reason Heuristics
PUP.Playtech
15.3.18.1

Rising Antivirus
Adware.Win32.Agent.kje
23.00.65.15128

File size:
649.3 KB (664,832 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\ptu4fd_tmp.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/18/2008 3:00:00 AM

Valid to:
4/19/2009 2:59:59 AM

Subject:
CN=Playtech Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Playtech Limited, L=Tortola, S=Not available, C=VG

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0CC633E902A022B96C9E1CB8C01869EA

File PE Metadata
Compilation timestamp:
4/1/2008 2:58:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:tTvr/GrQ/vKEBX7jmuE8aiy7z2nqOraM5PEHRdajd:tLy81RjmuEj7z2ntaM58HDap

Entry address:
0x240D3

Entry point:
B8, 88, 2E, 5B, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 14, 9F, 5C, 1B, 1B, D5, 30, D6, DD, C0, 0B, 76, B5, 62, 26, 1A, 3E, 70, 36, 48, BF, 78, 16, 0F, A2, 44, DF, 29, E5, 8A, 65, C6, 23, 14, 5C, 57, 4B, 52, C9, F3, 69, F0, A2, 88, DD, 1F, EA, 08, 38, 70, 52, A4, 83, 6B, D1, 12, 78, CD, 81, 27, 79, 23, EC, 4A, A8, D3, 00, CE, 7E, 16, F4, 16, 56, E3, 10, 66, 50, 3D, 45, C2, BC, A8, 0F, 4F, 7F, 7E, 2B, 06, 74, B4, 0F, 77, 6E...
 
[+]

Packer / compiler:
PECompact v2

Code size:
224 KB (229,376 bytes)

Remove ptu4fd_tmp.exe - Powered by Reason Core Security