!update.exe

The application !update.exe has been detected as a potentially unwanted program by 38 anti-malware scanners. According to AVG, this software downloads additional adware offers during setup.
MD5:
5f788cd477c0f61f1d52503b7b3793aa

SHA-1:
3b043829df3e94f950e44bc1d7559e37773ce6ce

Scanner detections:
38 / 68

Status:
Potentially unwanted

Analysis date:
4/1/2025 7:12:00 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Zusy.Elzob.1925
-40

AegisLab AV Signature
Troj.Downloader.W32.PurityScan.dx!c
2.1.4+

AhnLab V3 Security
Win-Trojan/Purityscan.71680.AH
2016.04.09

Avira AntiVirus
TR/Dldr.PuritySca.A
8.3.3.4

Arcabit
Trojan.Zusy.Elzob.D785
1.0.0.666

avast!
Win32:Trojan-gen
2014.9-170315

AVG
Downloader.Generic3
2018.0.2438

Baidu Antivirus
Win32.Trojan.WisdomEyes.151026.9950
4.0.3.17315

Bitdefender
Gen:Variant.Zusy.Elzob.1925
1.0.20.370

Clam AntiVirus
Win.Downloader.7995-1
0.98/21511

Comodo Security
TrojWare.Win32.TrojanDownloader.PuritySca.A0
24759

Dr.Web
Trojan.DownLoader.22753
9.0.1.074

Emsisoft Anti-Malware
Gen:Variant.Zusy.Elzob.1925
8.17.03.15.08

ESET NOD32
Win32/TrojanDownloader.PurityScan (variant)
11.13307

Fortinet FortiGate
W32/PurityScan.DX!tr.dldr
3/15/2017

F-Prot
W32/Downldr2.CMZ
v6.4.7.1.166

F-Secure
Gen:Variant.Zusy.Elzob.1925
11.2017-15-03_4

G Data
Gen:Variant.Zusy.Elzob.1925
17.3.25

IKARUS anti.virus
Trojan-Downloader.Win32.PurityScan
t3scan.2.0.9.0

K7 AntiVirus
Backdoor
13.221.19258

Kaspersky
Trojan-Downloader.Win32.PurityScan
14.0.0.-1314

Malwarebytes
Trojan.Downloader
v2017.03.15.08

McAfee
Generic Downloader
5600.6094

MicroWorld eScan
Gen:Variant.Zusy.Elzob.1925
18.0.0.222

NANO AntiVirus
Trojan.Win32.PurityScan.mxmy
1.0.18.7201

nProtect
Trojan-Downloader/W32.PurityScan.71680.D
16.04.08.01

Panda Antivirus
Trj/Genetic.gen
17.03.15.08

Qihoo 360 Security
Malware.Radar01.Gen
1.0.0.1120

Rising Antivirus
PE:Trojan.DL.Win32.PurityScan.dx!1145385 [F]
23.00.65.17313

Sophos
ClickSpring (PUA)
4.98

SUPERAntiSpyware
Adware.ClickSpring
8533

Total Defense
Win32/Clspring.GS
37.1.62.1

Trend Micro House Call
ADW_PURITYSCA.CD
7.2.74

Trend Micro
ADW_PURITYSCA.CD
10.465.15

Vba32 AntiVirus
suspected of Malware.Agent.16
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
48482

ViRobot
Trojan.Win32.Downloader.71680.AG[h]
2014.3.20.0

Zillya! Antivirus
Downloader.PurityScan.Win32.189
2.0.0.2773

File size:
70 KB (71,680 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temp\!update.exe

File PE Metadata
Compilation timestamp:
11/27/2006 4:57:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x10164

Entry point:
B8, 04, 0F, 43, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, D4, 9A, 7C, 5B, DF, 37, 98, D1, 58, 97, 86, BA, BF, 82, 94, DD, CF, CF, 9C, 05, B0, 11, 11, 8A, 5C, E0, DE, 56, C6, D9, 9A, 03, 35, 01, B8, B5, 81, 65, 70, D9, EE, 0B, 10, 79, FC, D7, 4B, FB, E7, F5, 70, CC, 50, 60, 3F, C9, D4, F3, 41, A1, 03, 11, AD, 35, 99, 23, 8F, 8A, 11, D9, 89, FF, 9D, B6, E8, AA, 6B, 7C, DE, 11, 40, 1D, 48, B2, 52, F5, F1, 98, C0, 5E, E3, CF, 9E...
 
[+]

Packer / compiler:
PECompact v2

Code size:
108 KB (110,592 bytes)

Remove !update.exe - Powered by Reason Core Security