PCPitstopErase.exe

PC Pitstop Erase

P.C. Pitstop LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PC Pitstop Erase Scheduler’.
Publisher:
PC Pitstop, LLC.  (signed by P.C. Pitstop LLC)

Product:
PC Pitstop Erase

Version:
1.1.6.0

MD5:
9659df0678f8867c436cefc3e1b0e327

SHA-1:
f198921d90830bacfcfe392c7cf24c0f805905d1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 6:38:40 AM UTC  (today)

File size:
797 KB (816,120 bytes)

Product version:
1.1.6.0

Copyright:
©2006 PC Pitstop, LLC. All rights reserved.

Original file name:
PCPitstopErase.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pcpitstop\erase\pcpitstoperase.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
12/29/2005 4:42:14 PM

Valid to:
2/22/2007 2:04:12 PM

Subject:
CN=P.C. Pitstop LLC, OU=Secure Application Development, O=P.C. Pitstop LLC, L=Dakota Dunes, S=South Dakota, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
3BBB20222A52CB85224042F980E841B3

File PE Metadata
Compilation timestamp:
7/27/2006 12:25:43 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.10

CTPH (ssdeep):
12288:L5BkGubtr6PWFfTcJrxk5B3LeM19NvNMhld6ivsvMF:dBk3bl6PKcpxkHbeMDN1suMF

Entry address:
0x208E0

Entry point:
E8, 2B, FD, FF, FF, 85, C0, 74, 2A, 56, 8B, 35, A8, A2, 49, 00, 6A, 00, FF, D6, 50, E8, 66, FE, FF, FF, 83, C4, 04, 68, BC, EE, 49, 00, FF, D6, 50, E8, 56, FE, FF, FF, 83, C4, 04, 5E, E9, F1, D5, 04, 00, 6A, 10, 68, 7C, BE, 49, 00, 68, 78, EE, 49, 00, 6A, 00, FF, 15, F0, B8, 4B, 00, 6A, FF, FF, 15, A4, A2, 49, 00, CC, 53, 55, 8B, 6C, 24, 0C, 56, 8B, F1, 39, 6E, 14, 73, 05, E8, 77, F1, 05, 00, 8B, 46, 14, 8B, 54, 24, 14, 2B, C5, 3B, C2, 73, 02, 8B, D0, 85, D2, 8B, 5C, 24, 1C, 74, 2E, 3B, D3, 8B, CA, 72, 02...
 
[+]

Entropy:
6.2751

Code size:
612 KB (626,688 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PC Pitstop Erase Scheduler

Command:
C:\Program Files\pcpitstop\erase\pcpitstoperase.exe \remindme


Scan PCPitstopErase.exe - Powered by Reason Core Security