How to remove dup2.exe

dup2.exe

The module dup2.exe has been detected as Adware.Agent

dup2.exe

dup2.exe is a Windows file recorded in the ThreatInfo database. It is associated with diablo2oo2's Universal Patcher. The reported company name is diablo2oo2. The current detection status is Adware.Agent, based on the latest analysis from 2025-12-29 23:02:32 (5 months ago).

If dup2.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Adware.Agent.

Product Name: diablo2oo2's Universal Patcher
Company Name: diablo2oo2
MD5: ba5ef48e2a48a58fa94ae515fe5d17c2
Size: 527 KB
First Published: 2025-12-29 23:02:32 (5 months ago)
Latest Published: 2025-12-29 23:02:32 (5 months ago)
Status: Adware.Agent (on last analysis)
Analysis Date: 2025-12-29 23:02:32 (5 months ago)
Signed By: diablo2oo2.cjb.net
Status: Valid

The signature on dup2.exe is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%profile%

ThreatInfo has observed dup2.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is New Zealand with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for dup2.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

dup2.exe is identified as pe for 32 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 32
Image Base: 0x00400000
Entry Address: 0x0001a230

PE Sections:

Name Size of data MD5
.text 120832 d0e6ee7815ba386f7851cec5a2eaf205
.rdata 5632 42ff127a13f1d90081a9074230f339c9
.data 265728 cecd105f35f326fd6390c99cc4e0c540
.rsrc 131072 cce86db7109991f4dfada1c7acbd83a9
.reloc 11776 351e76bbf09d58904d77418751176890

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information:

Download GridinSoft Anti-Malware - Removal tool for dup2.exe