updater.exe

Softoware LLC

The application updater.exe, “updater 2.0.7 © Network Security Guard, Inc, 2014” by Softoware has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Network Security Guard  (signed by Softoware LLC)

Product:
Network Security Guard

Description:
updater 2.0.7 © Network Security Guard, Inc, 2014

Version:
2.0.7

MD5:
043cfcc5b0d07f064d43481d0d16fd7e

SHA-1:
f6ae83e62d6e69d9c40173de603136f812cbce98

SHA-256:
49a0be0cef518b1bc3dd548cc23e8f8f56ef6ae4d8a343ba5b872458951d5fcb

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:36:04 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.7.23.17

File size:
451.9 KB (462,768 bytes)

Product version:
2.0.7

Copyright:
Copyright (C) 2016 Network Security Guard

Original file name:
updater.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\network security guard\updater.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
5/10/2015 8:00:00 PM

Valid to:
5/10/2016 7:59:59 PM

Subject:
CN=Softoware LLC, OU=Softoware LLC, O=Softoware LLC, STREET="1225 FRANKLIN AVENUE, SUITE 325", L=Garden City, S=New York, PostalCode=11530, C=US

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
6DC73DE107D58AD4D4BA573833F01896

File PE Metadata
Compilation timestamp:
3/23/2016 5:41:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:DMNndV/tDchO6tIRTDM6JSBF+LEomGKbOGf14CeN1t9ZhraiCZMoPPWLi:uVlQyM6JSeLu6Gf14tZ8iCZtPWm

Entry address:
0x2CC8F

Entry point:
E8, 4D, 05, 00, 00, E9, 80, FE, FF, FF, 55, 8B, EC, 6A, FF, 68, A7, 09, 44, 00, 64, A1, 00, 00, 00, 00, 50, 51, 53, 56, 57, A1, 0C, D0, 44, 00, 33, C5, 50, 8D, 45, F4, 64, A3, 00, 00, 00, 00, 89, 65, F0, FF, 75, 08, 83, 65, FC, 00, E8, 63, FD, FF, FF, 59, EB, 08, B8, D7, CC, 42, 00, C3, 33, C0, 8B, 4D, F4, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5E, 5B, 8B, E5, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 53, 56, 6A, 17, E8, ED, 30, 01, 00, 85, C0, 74, 05, 8B, 4D, 08, CD, 29, 33, F6, 8D, 85, DC, FC, FF, FF, 68...
 
[+]

Entropy:
6.0822

Code size:
255 KB (261,120 bytes)

Remove updater.exe - Powered by Reason Core Security