PwdPrompt.exe

Folder Protect

NewSoftwares.net Inc. SDN. BHD.

The application PwdPrompt.exe, “Security Data Software” by NewSoftwares.net SDN. BHD has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Newsoftwares.net, Inc  (signed by NewSoftwares.net Inc. SDN. BHD.)

Product:
Folder Protect

Description:
Security Data Software

Version:
1.5.1.0

MD5:
b59a35e808ad0bd993aa5fa77a20f381

SHA-1:
88f75bcaa7d4cfd4a19decc5d7c81e8d5227863f

SHA-256:
9120c4fb36c0d7c821c317a16bb90deba8b3b5b97714d2d8deb2ec5f0a54a522

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
11/27/2024 3:43:50 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewSoftw
17.3.9.14

File size:
1.3 MB (1,375,184 bytes)

Product version:
1.5.1.0

Copyright:
Copyrights (C) 2009, Newsoftwares.net, Inc All Right Reserved

Original file name:
PwdPrompt.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\folder protect\pwdprompt.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/3/2009 2:53:54 AM

Valid to:
2/3/2012 2:53:54 AM

Subject:
E=president@newsoftwares.net, CN=NewSoftwares.net Inc. SDN. BHD., O=NewSoftwares.net Inc. SDN. BHD., C=MY

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011F3BFCD88E

File PE Metadata
Compilation timestamp:
12/4/2009 9:38:29 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x126253

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, D6, 05, A2, 4F, D8, AC, 61, DF, F4, E2, 3D, B0, 99, 42, E6, CD, 05, 25, F0, 35, 85, 5F, 3A, A5, 5C, 9E, B3, 53, A7, 1F, B5, 03, 6B, 04, B8, 26, FB, AB, F3, AD, 17, 5D, 9C, DD, 02, F2, 0C, 11, F7, 00, CD, DD, ED, D8, 4B, DD, F7, 00, CD, DD, ED, D8, 4B, DD, E9, C9, 4B, 00, 00, E9, DD, 4B, 00, 00, E9, D8, 4B, 00, 00, E8, 5E, FB, FF, FF, 4E, DD, 00, 00, 42, 8F, 00, 00, 48, 2B, 04, 85, 2D, 5E, 41, C3, 4A, B0, D4, BC, 94, FC, 71, 30, EA, E1, 70, 33, F2, 05, 49, CF, 0F...
 
[+]

Entropy:
6.7002

Packer / compiler:
MoleBox v2.0

Remove PwdPrompt.exe - Powered by Reason Core Security