ytd.exe

YTD

Pepak

The application ytd.exe by Pepak has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler.
Publisher:
Pepak  (signed and verified)

Product:
YTD

Version:
1.15.0.888

MD5:
bd0c2a3936a95f8a3fca0451fa3be337

SHA-1:
535ec3d0e85a9b5e1626a9e418697cddf0ef76ee

SHA-256:
7efb11663ec8d86e7dd86c6d946d93c730f005df0d78b00ed709c4085cac2a9f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
12/26/2024 9:39:10 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Pepak (M)
16.7.13.8

File size:
1.2 MB (1,244,672 bytes)

Product version:
1.15.0.888

Copyright:
(c) 2009-11 Pepak

Original file name:
ytd.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\ytd\ytd.exe

Digital Signature
Signed by:

Authority:
Pepak (root CA)

Valid from:
12/31/2011 7:17:32 AM

Valid to:
12/31/2012 7:17:31 AM

Subject:
CN=Pepak, E=http://www.pepak.net

Issuer:
CN=Pepak (root CA), E=http://www.pepak.net

Serial number:
D6680FCC835300A2462CD399490DD669

File PE Metadata
Compilation timestamp:
8/19/2012 3:56:57 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.25

CTPH (ssdeep):
24576:pbY6CHmfAdsbiaYb3hDrUjjcpBCQc+MCrtyC:pbiaYb3PpBCQz9rtR

Entry address:
0xF8234

Entry point:
55, 8B, EC, 83, C4, F0, A1, A0, 91, 50, 00, C6, 00, 01, B8, 9C, 49, 4F, 00, E8, A8, 0F, F1, FF, E8, 23, F8, F7, FF, E8, 32, D3, F0, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
987 KB (1,010,688 bytes)

Scheduled Task
Task name:
{5661328C-43A1-4D1F-889D-DA1CA40692C1}

Trigger:
Registration (Runs on registration)


Remove ytd.exe - Powered by Reason Core Security