updatepacklive-16.5.15.exe

Операционная система Microsoft Windows

Smart Isteit, TOV

While the file properties state the file is developed by 'Microsoft Corporation', this is not the case and it is designed just to look like a legitimate Microsoft system file. The executable updatepacklive-16.5.15.exe, “Исполняемый файл для игры "Солитер"” has been detected as malware by 1 anti-virus scanner.
Publisher:
Microsoft Corporation  (signed by Smart Isteit, TOV)

Product:
Операционная система Microsoft® Windows®

Description:
Исполняемый файл для игры "Солитер"

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
76db394ed2911d589cef99af3b69a871

SHA-1:
0e76529bc39aad430f5a52a85f519e1aebdb6644

SHA-256:
41d182ba69c33b2ccf4bf886244db5678e3df30a6212023ecb5bad97090357f9

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
12/26/2024 5:02:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.2.24.14

File size:
2.9 MB (3,069,016 bytes)

Product version:
6.1.7600.16385

Copyright:
© Корпорация Майкрософт. Все права защищены.

Original file name:
freecell.exe.mui

File type:
Executable application (Win32 EXE)

Common path:
C:\windows\temp\rar$exa0.829\updatepacklive-16.5.15.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
8/18/2016 3:00:00 AM

Valid to:
5/11/2017 2:59:59 AM

Subject:
CN="Smart Isteit, TOV", OU=IT, O="Smart Isteit, TOV", STREET="Vulytsya Startova, Budynok 3", L=Misto Dnipropetrovsk, S=Dnipropetrovska, PostalCode=49041, C=UA

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
755F730067677AB16CFA5C2ED8D59C72

File PE Metadata
Compilation timestamp:
5/17/2014 11:39:27 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

Entry address:
0x2E1500

Entry point:
6A, 70, 68, A0, 31, 6E, 00, E8, F4, 01, 00, 00, 33, FF, 57, FF, 15, 00, 30, 6E, 00, 66, 81, 38, 4D, 5A, 75, 1F, 8B, 48, 3C, 03, C8, 81, 39, 50, 45, 00, 00, 75, 12, 0F, B7, 41, 18, 3D, 0B, 01, 00, 00, 74, 1F, 3D, 0B, 02, 00, 00, 74, 05, 89, 7D, E4, EB, 27, 83, B9, 84, 00, 00, 00, 0E, 76, F2, 33, C0, 39, B9, F8, 00, 00, 00, EB, 0E, 83, 79, 74, 0E, 76, E2, 33, C0, 39, B9, E8, 00, 00, 00, 0F, 95, C0, 89, 45, E4, 89, 7D, FC, 6A, 02, 5B, 53, FF, 15, 38, 30, 6E, 00, 59, 83, 0D, B8, EF, 91, 00, FF, 83, 0D, BC, EF...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v7.1

Code size:
2.9 MB (3,022,848 bytes)

Remove updatepacklive-16.5.15.exe - Powered by Reason Core Security