SE.exe

SE

Eli Dahan

The is the installer for the WebPick InstalleRex download manager which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed without consent. The application SE.exe by Eli Dahan has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
SkypEmoticons  (signed by Eli Dahan)

Product:
SE

Description:
SkypEmoticons

Version:
1.0.0.19

MD5:
42aec3ab27425732236b89ece36a77e0

SHA-1:
fbf0c0636ddf078b1b43f4f80d4292b449b124a9

SHA-256:
db82944eb9981f3d6fec5fb5ee477b23b6420b7865f25311e9f403492d70ea82

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 12:37:24 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.WebPick (M)
17.2.8.2

File size:
5.6 MB (5,842,336 bytes)

Product version:
1.0.0.19

Copyright:
SkypEmoticons. All rights reserved.

Original file name:
SE.exe

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\appdata\roaming\skypemoticons\se.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
6/10/2013 1:00:00 AM

Valid to:
6/11/2014 12:59:59 AM

Subject:
CN=Eli Dahan, O=Eli Dahan, STREET=Halapid 3, L=Ramat Gan, S=Center, PostalCode=52573, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00864002C7281B93C1609931176B93A6AE

File PE Metadata
Compilation timestamp:
9/11/2013 11:04:24 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0xE8BDB0

Entry point:
60, BE, 00, 20, D1, 00, 8D, BE, 00, F0, 6E, FF, 57, 83, CD, FF, EB, 10, 90, 90, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 28, 8B, 1E, 83, EE, FC, 11, DB, 72, 1F, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C9, EB, 52, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 75, D1, F8, 89...
 
[+]

Packer / compiler:
UPX 2.90LZMA

Code size:
5.5 MB (5,742,592 bytes)

Remove SE.exe - Powered by Reason Core Security