protect.exe

Shan Feng

The application protect.exe by Shan Feng has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(Guntony_protect)”.
Publisher:
Shan Feng  (signed and verified)

Version:
50.14.2661.78

MD5:
e7df232fb4670f5c7a517d7fffb0a8fc

SHA-1:
41d75f03ac00a0e597ef91ea9fd890aa6c2a1a11

SHA-256:
15a2c138edb4d8e2b097579762df7aa3e90503820219ed040d3002ddf265c16f

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 1:41:54 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Elex (M)
16.10.15.5

File size:
295.9 KB (302,976 bytes)

Product version:
50.14.2661.78

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\guntony\protect\protect.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
5/6/2016 5:00:00 AM

Valid to:
10/23/2016 4:59:59 AM

Subject:
CN=Shan Feng, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
5468DE414178163609F5122D532EB4F4

File PE Metadata
Compilation timestamp:
5/12/2016 1:06:51 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:0hwGJ0oaP711ypDfBc/i2h+UjDx1u1nbETgDA4+ApZW3vHnrPrRMEnRWp+Ju6PVq:01J0oaP7aDp4XObVA43onr3uG/rN4

Entry address:
0x1A538

Entry point:
E8, 35, CC, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, A0, 24, 44, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, 2B, 66, 00, 00, 59, FF, 34, F5, A0, 24, 44, 00, FF, 15, A4, 40, 43, 00, 5E, 5D, C3, 56, 57, BE, A0, 24, 44, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, 08, 41, 43, 00, 53, E8, A5, CE, FF, FF, 83, 27, 00, 59, 83, C7, 08, 81, FF, C0, 25, 44, 00, 7C, D8, 5B, 83, 3E, 00, 74, 0E, 83, 7E, 04, 01, 75, 08, FF, 36, FF, 15...
 
[+]

Code size:
201 KB (205,824 bytes)

Service
Display name:
Protect Service(Guntony_protect)

Service name:
Guntony_protect

Description:
To ensure your Guntony software integrity. If this service is disabled or stopped, your Guntony software will not be kept integrity check. This service uninstalls itself when there is no Guntony softw

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove protect.exe - Powered by Reason Core Security