registro2012.exe

Gerenciador de Download

BR SOFTWARE LLC

The application registro2012.exe by BR SOFTWARE has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
ASSISTENTE DE DOWNLOAD  (signed by BR SOFTWARE LLC)

Product:
Gerenciador de Download

Version:
1.0.0

MD5:
ff60b5031a43a2fb3652dab8d60e72d9

SHA-1:
7505b5493c5d620ecb27b1c3cc92a790f16b0c2a

SHA-256:
8e54e5970be7704860761c209d0353b3f0494d9fb7d9e2b35f152ef245a11042

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 1:31:38 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BR Software (M)
16.10.9.6

File size:
990.4 KB (1,014,192 bytes)

Product version:
1.0.0

Copyright:
© ASSISTENTE DE DOWNLOAD

Original file name:
acelerador.exe

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Common path:
C:\users\{user}\downloads\registro2012.exe

Digital Signature
Signed by:

Authority:
Starfield Technologies, Inc.

Valid from:
4/17/2012 7:18:35 PM

Valid to:
4/17/2013 4:03:06 PM

Subject:
CN=BR SOFTWARE LLC, O=BR SOFTWARE LLC, L=Lewes, S=DE, C=US

Issuer:
SERIALNUMBER=10688435, CN=Starfield Secure Certification Authority, OU=http://certificates.starfieldtech.com/repository, O="Starfield Technologies, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4B201CE7EB9204

File PE Metadata
Compilation timestamp:
5/6/2009 2:23:44 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:Mx4Mi4+EaWyZDAbKh6tBoJU0DuF4jovaVGMwhJE/Clpzwu:wcEaWjrjiA4jova8Mz/Clpzwu

Entry address:
0x8B902

Entry point:
E8, 2D, 79, 00, 00, E9, 16, FE, FF, FF, 8B, 44, 24, 04, 33, C9, 3B, 04, CD, 90, 46, 4D, 00, 74, 12, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0C, 6A, 0D, 58, C3, 8B, 04, CD, 94, 46, 4D, 00, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, C3, E8, 5E, 3D, 00, 00, 85, C0, 75, 06, B8, F8, 47, 4D, 00, C3, 83, C0, 08, C3, E8, 4B, 3D, 00, 00, 85, C0, 75, 06, B8, FC, 47, 4D, 00, C3, 83, C0, 0C, C3, 56, E8, E7, FF, FF, FF, 8B, 4C, 24, 08, 51, 89, 08, E8, 8D, FF, FF, FF, 59, 8B, F0...
 
[+]

Code size:
684 KB (700,416 bytes)

Remove registro2012.exe - Powered by Reason Core Security