hsr4w2gscmzw.exe

Clean Disk Security

KOMP-GARANT

The executable hsr4w2gscmzw.exe, “Clean Free Space of Drives (security)” has been detected as malware by 1 anti-virus scanner.
Publisher:
Kevin Solway  (signed by KOMP-GARANT)

Product:
Clean Disk Security

Description:
Clean Free Space of Drives (security)

Version:
7.8.3.1

MD5:
9df47d424316513426df22dd81223a6b

SHA-1:
0e389557e9eaf87d9d7ef73f53cbec1d270f73b8

SHA-256:
1bdfd5de261691b465b3656f23413c34c49899e1b10c67ce559de63d04317ad6

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
11/15/2024 6:22:57 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
17.3.4.11

File size:
755.5 KB (773,632 bytes)

Product version:
7.50

Copyright:
Copyright © Kevin Solway 1998-2004

Trademarks:
Clean Disk Security TM Kevin Solway 1999

Original file name:
Clndsk.exe

File type:
Executable application (Win32 EXE)

Language:
English (Australia)

Common path:
C:\users\{user}\appdata\local\temp\hsr4w2gscmzw.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
10/8/2015 5:00:00 PM

Valid to:
10/8/2016 4:59:59 PM

Subject:
CN="""KOMP-GARANT"",OOO", O="""KOMP-GARANT"",OOO", STREET="d. 4 korp. 3 kv. VI, ul.Kirovogradskay", L=Moscow, S=Moscow, PostalCode=117587, C=RU

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00DDF03E3656C370A166F00225E6978B94

File PE Metadata
Compilation timestamp:
11/29/1979 10:18:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x973FF

Entry point:
8B, 0D, AC, C1, 49, 00, 0F, B6, 09, 80, E9, B0, 8A, C9, 83, E9, 08, 90, 75, D3, E9, E1, 93, 04, 00, 40, 00, 48, 10, 40, 00, 50, 10, 40, 00, 58, 10, 40, 00, 60, 10, 40, 00, 68, 10, 40, 00, 70, 10, 40, 00, 78, 10, 40, 00, 80, 10, 40, 00, 88, 10, 40, 00, 90, 10, 40, 00, 98, 10, 40, 00, A0, 10, 40, 00, A8, 10, 40, 00, B0, 10, 40, 00, B8, 10, 40, 00, C0, 10, 40, 00, C8, 10, 40, 00, D0, 10, 40, 00, D8, 10, 40, 00, E0, 10, 40, 00, E8, 10, 40, 00, F0, 10, 40, 00, F8, 10, 40, 00, 00, 11, 40, 00, 08, 11, 40, 00, 10...
 
[+]

Code size:
606.5 KB (621,056 bytes)

Remove hsr4w2gscmzw.exe - Powered by Reason Core Security