schedc.exe

schedc

SIEN INTERNET PRODUCTS LTD

The application schedc.exe by SIEN INTERNET PRODUCTS has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
SIEN INTERNET PRODUCTS LTD  (signed and verified)

Product:
schedc

Version:
3.1.2.0

MD5:
19809d38613d9089913165f71a96f3e5

SHA-1:
6c73e8f79f39f21ab4b771ac2fa261c4dc5cfd0e

SHA-256:
a81fcbbad47077b3e0624c6686c9fc231bdd02d4aeb1de6bb40a78bf5b247570

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/28/2024 3:12:45 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Sien.SIENINTE (M)
16.3.25.8

File size:
21.5 KB (21,992 bytes)

Product version:
3.1.2.0

Copyright:
Copyright © 2015

Original file name:
schedc.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\roaming\air privacy shield\air privacy shield 3.1.2\install\a822b97\schedc.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
6/18/2015 7:38:06 AM

Valid to:
6/18/2016 7:38:06 AM

Subject:
CN=SIEN INTERNET PRODUCTS LTD, O=SIEN INTERNET PRODUCTS LTD, L=London, S=LONDON, C=GB

Issuer:
CN=GlobalSign CodeSigning CA - SHA256 - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112197E7BBA82299D8F1DCEDCE8898C6F8C6

File PE Metadata
Compilation timestamp:
1/22/2016 1:55:51 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:+rMRxtMNLUcVVxjTMBa4u46hPszfI+OxoTCWZtgNRIYfrWIdm:+rqmPjlPQf2xkCAwRtDW5

Entry address:
0x5FCA

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 50, 00, 00, 0C, 00, 00, 00, CC, 3F, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.4187

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
16 KB (16,384 bytes)

Remove schedc.exe - Powered by Reason Core Security