pmbxag.exe

Tech Matrix Infosolutions Inc

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘YodaShield Total Security 2014 Wallet Agent’.
Publisher:
YodaShield Total Security 2014  (signed by Tech Matrix Infosolutions Inc)

Product:
YodaShield Total Security 2014

Description:
YodaShield Total Security 2014 Password Manager Agent

Version:
17.21.0.924 102477

MD5:
43e71802b1c4e91a21e8342067529cb7

SHA-1:
724ac8ed7f7af69faf23d0ac983cb7aebcaa392a

SHA-256:
3e6abd906009d54dffdcf08f3a215bbb460f8e975d9d02b24cdd62c8f765b033

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 2:23:22 AM UTC  (today)

File size:
551.6 KB (564,808 bytes)

Product version:
17.21.0.924 102477

Copyright:
©TechMatrix Info Solutions

Original file name:
pmbxag.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\yodashield total security 2014\yodashield total security 2014\pmbxag.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/20/2013 7:00:00 PM

Valid to:
11/21/2014 6:59:59 PM

Subject:
CN=Tech Matrix Infosolutions Inc, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Tech Matrix Infosolutions Inc, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6A3942872A796031DD740CF3447B910C

File PE Metadata
Compilation timestamp:
10/28/2013 1:10:57 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:iWdp1BmBV5gRuhoV53Hwe/n/TNLtkAtL5wO2XFSxrJ:iWdp1Bmj2rnpLttL5BF

Entry address:
0x39940

Entry point:
48, 83, EC, 28, E8, 3B, 03, 00, 00, 48, 83, C4, 28, E9, 26, FD, FF, FF, FF, 25, 18, 5B, 00, 00, FF, 25, 0A, 5B, 00, 00, CC, CC, 48, 89, 4C, 24, 08, 48, 81, EC, 88, 00, 00, 00, 48, 8D, 0D, BD, F5, 01, 00, FF, 15, 5F, 57, 00, 00, 48, 8B, 05, A8, F6, 01, 00, 48, 89, 44, 24, 58, 45, 33, C0, 48, 8D, 54, 24, 60, 48, 8B, 4C, 24, 58, E8, B3, 03, 00, 00, 48, 89, 44, 24, 50, 48, 83, 7C, 24, 50, 00, 74, 41, 48, C7, 44, 24, 38, 00, 00, 00, 00, 48, 8D, 44, 24, 48, 48, 89, 44, 24, 30, 48, 8D, 44, 24, 40, 48, 89, 44, 24...
 
[+]

Entropy:
6.4509

Code size:
247 KB (252,928 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
YodaShield Total Security 2014 Wallet Agent

Command:
"C:\Program Files\yodashield total security 2014\yodashield total security 2014\pmbxag.exe"


Scan pmbxag.exe - Powered by Reason Core Security