pcmaticrt.exe

SuperShield Realtime Protection

P.C. Pitstop LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PC MaticRT’.
Publisher:
PC Pitstop LLC  (signed by P.C. Pitstop LLC)

Product:
SuperShield Realtime Protection

Description:
PC Pitstop PC Matic SuperShield

Version:
1.0.0.42

MD5:
88949330598e4e334ef0838bac9dbcaf

SHA-1:
e22f1f80735679cd5ea9bb8eef4f0b7fa6e21122

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:49:38 PM UTC  (today)

File size:
1.1 MB (1,106,544 bytes)

Product version:
1.0.0.42

Copyright:
2014 (c) PC Pitstop LLC. All rights reserved.

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pcpitstop\supershield\pcmaticrt.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/4/2013 6:00:00 PM

Valid to:
2/20/2015 5:59:59 PM

Subject:
CN=P.C. Pitstop LLC, OU=SECURE APPLICATION DEVELOPMENT, O=P.C. Pitstop LLC, L=Dakota Dunes, S=South Dakota, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
398EF05E9772B034B6F033FC5DBE28B9

File PE Metadata
Compilation timestamp:
1/14/2014 1:46:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:XGjAWk8aKz07jZkXO2clfHiV06/BfdjlTJFKED5pBD:X9uabjuclfHiV06/BfdjlTSED9D

Entry address:
0x218EB

Entry point:
E8, E0, E5, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, 68, 90, 19, 42, 00, 64, FF, 35, 00, 00, 00, 00, 8B, 44, 24, 10, 89, 6C, 24, 10, 8D, 6C, 24, 10, 2B, E0, 53, 56, 57, A1, 10, 98, 45, 00, 31, 45, FC, 33, C5, 50, 89, 65, E8, FF, 75, F8, 8B, 45, FC, C7, 45, FC, FE, FF, FF, FF, 89, 45, F8, 8D, 45, F0, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F0, 64, 89, 0D, 00, 00, 00, 00, 59, 5F, 5F, 5E, 5B, 8B, E5, 5D, 51, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 07, 83, F8, FE, 74, 0D, 8B, 4F, 04, 03...
 
[+]

Entropy:
6.5091

Code size:
286 KB (292,864 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PC MaticRT

Command:
C:\Program Files\pcpitstop\supershield\pcmaticrt.exe


Scan pcmaticrt.exe - Powered by Reason Core Security