loader32.exe

ExploitShield

ZeroVulnerabilityLabs, Inc.

It runs as a scheduled task under the Windows Task Scheduler named ExploitShield triggered to execute each time a user logs in. This is installed with ZeroVulnerabilityLabs ExploitShield version 0.8.1 beta.
Publisher:
ZeroVulnerabilityLabs, Inc.  (signed and verified)

Product:
ExploitShield

Description:
ExploitShield Loader

Version:
0.8.0.1

MD5:
3a0da129384eb107a7fa3db4e350dbcb

SHA-1:
8805c0546ebf8ea7e9636343d321a1604db0e7fa

SHA-256:
faebc3120038dd9c1849bf0aa8a9d35adc9b8303ca3ac0d2030f2af2c7b89c2b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
1/12/2025 10:45:28 PM UTC  (today)

File size:
45.2 KB (46,296 bytes)

Product version:
0.8.0.1

Copyright:
(c) 2012 ZeroVulnerabilityLabs, Inc.

Original file name:
Loader

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\zerovulnerabilitylabs\exploitshield\loader32.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
5/29/2012 2:00:00 AM

Valid to:
6/3/2013 2:00:00 PM

Subject:
CN="ZeroVulnerabilityLabs, Inc.", O="ZeroVulnerabilityLabs, Inc.", L=San Jose, S=California, C=US

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
07CA76C80E17FD2CA42587E9B14D22CE

File PE Metadata
Compilation timestamp:
11/30/2012 1:09:15 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
384:8esFwQStHvd7RyxwiHeBcdtfwOAH896vKwUbkF4+UqGoYY6lyZ9mTklsSZZv/K6O:8XytHvVR8dtj1QBUSAjob6lQukZKgi

Entry address:
0x110B4

Entry point:
E9, 17, 21, 00, 00, E9, A2, 1F, 00, 00, E9, 11, 3D, 00, 00, E9, 78, 13, 00, 00, E9, 5B, 3D, 00, 00, E9, C2, 1F, 00, 00, E9, 49, 1D, 00, 00, E9, 6C, 1F, 00, 00, E9, AF, 24, 00, 00, E9, D0, 3C, 00, 00, E9, 3D, 34, 00, 00, E9, B6, 1F, 00, 00, E9, 51, 3D, 00, 00, E9, D2, 36, 00, 00, E9, 9B, 1F, 00, 00, E9, F4, 3C, 00, 00, E9, 3D, 1C, 00, 00, E9, C2, 2D, 00, 00, E9, 1D, 1F, 00, 00, E9, B8, 34, 00, 00, E9, 6B, 1C, 00, 00, E9, 0C, 3D, 00, 00, E9, C5, 3C, 00, 00, E9, 5E, 30, 00, 00, E9, BF, 1E, 00, 00, E9, 4A, 2A...
 
[+]

Developed / compiled with:
Microsoft Visual C++ 8.0 (Debug)

Code size:
19.5 KB (19,968 bytes)

Scheduled Task
Task name:
ExploitShield

Trigger:
Logon (Runs on logon)


The file loader32.exe has been discovered within the following program.

Publisher's description - “Every week new financial, state-sponsored and commercial espionage targeted attacks are discovered. These sophisticated advanced persistent threats use arsenals of vulnerability exploits that are weaponized to steal confidential information and trade secrets.”
www.zerovulnerabilitylabs.com
About 13% of users remove it
 
Powered by Should I Remove It?

Scan loader32.exe - Powered by Reason Core Security