_psdel.exe

Proxima Software _psdel

Limited Liability Company

The application _psdel.exe by Limited Liability Company has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Proxima Software  (signed by Limited Liability Company )

Product:
Proxima Software _psdel

Description:
_psdel

Version:
2, 0, 0, 1

MD5:
00095377d9588e924852b63982ea175e

SHA-1:
e18028c3b3d55db9fa0eba3197f560a2640daf0d

SHA-256:
69470c5103b4feea7343296bcad653f6e3b61b2dab6e2696ef236a142bbf0944

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/26/2024 5:31:45 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ITVA.LimitedLiabilityCompany (M)
15.10.12.14

File size:
282.6 KB (289,400 bytes)

Product version:
2, 0, 0, 1

Copyright:
Copyright © 1998-2015, Proxima Software.

Original file name:
_psdel.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\_psdel.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/27/2014 2:00:00 AM

Valid to:
10/28/2015 1:59:59 AM

Subject:
CN="Limited Liability Company ""Proxima SFT""", O="Limited Liability Company ""Proxima SFT""", STREET=Podolskikh Kursantov Street, STREET=18-1-559, L=Moscow, S=Moscow, PostalCode=117545, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
4BA63201E321418FF839AA5A0634222F

File PE Metadata
Compilation timestamp:
8/29/2015 10:46:56 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:m5i2CxG3A+x/8LDtsgy7geKJgwIHaQsO2qsv1AQ:Ii2gSx/8LxsnBKJfQdzsv5

Entry address:
0x18E6

Entry point:
E8, E3, 06, 00, 00, E9, 4E, FE, FF, FF, 55, 8B, EC, 6A, 00, FF, 15, 58, D0, 43, 00, FF, 75, 08, FF, 15, 54, D0, 43, 00, 68, 09, 04, 00, C0, FF, 15, 5C, D0, 43, 00, 50, FF, 15, 60, D0, 43, 00, 5D, C3, 55, 8B, EC, 81, EC, 24, 03, 00, 00, 6A, 17, E8, 9E, 6A, 03, 00, 85, C0, 74, 05, 6A, 02, 59, CD, 29, A3, D0, 69, 44, 00, 89, 0D, CC, 69, 44, 00, 89, 15, C8, 69, 44, 00, 89, 1D, C4, 69, 44, 00, 89, 35, C0, 69, 44, 00, 89, 3D, BC, 69, 44, 00, 66, 8C, 15, E8, 69, 44, 00, 66, 8C, 0D, DC, 69, 44, 00, 66, 8C, 1D, B8...
 
[+]

Entropy:
6.5849

Code size:
238.5 KB (244,224 bytes)

Remove _psdel.exe - Powered by Reason Core Security