PWRISOVM.EXE

PowerISO Virtual Drive Manager

Power Software Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PWRISOVM.EXE’.
Publisher:
Power Software Ltd  (signed by Power Software Limited)

Product:
PowerISO Virtual Drive Manager

Version:
6, 4, 0, 0

MD5:
192df648c4a695ad298b92a9604524c0

SHA-1:
6bcfe1e0208a007be68c2d34e2e556085f0a41ba

SHA-256:
5043187b215dcae693cfba005440fb61566634560834666f98aedfae0afd1fc8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
11/27/2024 1:34:23 AM UTC  (today)

File size:
398.9 KB (408,512 bytes)

Product version:
6, 4, 0, 0

Copyright:
Copyright (C) 2004-2015

Original file name:
PWRISOVM.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\poweriso\pwrisovm.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
12/17/2015 7:00:00 PM

Valid to:
6/25/2017 7:59:59 PM

Subject:
CN=Power Software Limited, O=Power Software Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
2E3B3D0363ACEC80699F4CBF1A5F09DD

File PE Metadata
Compilation timestamp:
10/5/2015 8:37:35 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:tX+s6SG+wwsweb3BRkGPyrNbfbdghByKMIVIa/HbrbfPFJJn:tX+s1G7wsLb3PsbdghBXcGHb/ftJx

Entry address:
0xB1A0

Entry point:
48, 8B, C4, 48, 81, EC, A8, 00, 00, 00, 48, 89, 58, 18, 48, 89, 78, 20, 48, 8D, 48, 88, FF, 15, A4, 92, 01, 00, FF, 15, 96, 92, 01, 00, 48, 8B, C8, 33, D2, 41, B8, 94, 00, 00, 00, FF, 15, 7D, 92, 01, 00, 48, 8B, D8, 48, 85, C0, 75, 0A, B8, FF, 00, 00, 00, E9, 5A, 02, 00, 00, C7, 00, 94, 00, 00, 00, 48, 8B, C8, FF, 15, 54, 91, 01, 00, 85, C0, 75, 1E, FF, 15, 5A, 92, 01, 00, 48, 8B, C8, 4C, 8B, C3, 33, D2, FF, 15, 3C, 92, 01, 00, B8, FF, 00, 00, 00, E9, 29, 02, 00, 00, 8B, 43, 10, 89, 05, 65, 59, 03, 00, 8B...
 
[+]

Entropy:
6.2077

Code size:
140 KB (143,360 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PWRISOVM.EXE

Command:
C:\Program Files\poweriso\pwrisovm.exe -startup