IOProtect.exe

IO Entertainment Co., Ltd.

Publisher:
IO  (signed by IO Entertainment Co., Ltd.)

Description:
SP IOProtect

Version:
2009, 4, 17, 0

MD5:
738921186a02a1acab9ab1e757e653ec

SHA-1:
e5ecf3791271395297396f8c026f9589e22e5ad1

SHA-256:
159588b77a707758e2fbd56ff1dfaf845c26248b02fa52af13e17c402f791f83

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
11/24/2024 6:42:34 AM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
Packed/Themida
7.1.1

Trend Micro House Call
TROJ_GEN.F47V0708
7.2.303

File size:
681.3 KB (697,688 bytes)

Product version:
2009, 4, 17, 0

Copyright:
Copyright ⓒ 2003

Original file name:
IOProtect.exe

File type:
Executable application (Win32 EXE)

Language:
Korean (Korea)

Common path:
C:\Program Files\survival project\ioprotect.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/3/2008 7:00:00 PM

Valid to:
6/7/2009 6:59:59 PM

Subject:
CN="IO Entertainment Co., Ltd.", OU=Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="IO Entertainment Co., Ltd.", L=Guro-gu, S=Seoul, C=KR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
64EB01DECCC24B753FC20809B31A9C75

File PE Metadata
Compilation timestamp:
4/16/2009 8:55:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:PJwLjFn3nqFZBiY/PnkVNl5wjAfy5j3ZnckiiOB47zg79XHHY/WBUqg1USA1CPAh:BwLhaZ9Gmax4479XY/xUSooAAM

Entry address:
0x19014

Entry point:
B8, 00, 00, 00, 00, 60, 0B, C0, 74, 68, E8, 00, 00, 00, 00, 58, 05, 53, 00, 00, 00, 80, 38, E9, 75, 13, 61, EB, 45, DB, 2D, 37, 90, 41, 00, FF, FF, FF, FF, FF, FF, FF, FF, 3D, 40, E8, 00, 00, 00, 00, 58, 25, 00, F0, FF, FF, 33, FF, 66, BB, 19, 5A, 66, 83, C3, 34, 66, 39, 18, 75, 12, 0F, B7, 50, 3C, 03, D0, BB, E9, 44, 00, 00, 83, C3, 67, 39, 1A, 74, 07, 2D, 00, 10, 00, 00, EB, DA, 8B, F8, B8, 65, 53, 0B, 00, 03, C7, B9, 6D, 92, 01, 00, 03, CF, EB, 0A, B8, 65, 53, 4B, 00, B9, 6D, 92, 41, 00, 50, 51, E8, 87...
 
[+]

Entropy:
7.8398

Packer / compiler:
Themida/WinLicense V1.8.0.2 +

Code size:
52 KB (53,248 bytes)

The file IOProtect.exe has been discovered within the following programs.

Survival Project  by survival
www.survival.com.my
About 3% of users remove it
 
Powered by Should I Remove It?

Scan IOProtect.exe - Powered by Reason Core Security