autoexe.exe

autoexe

PODCornCommunication. Co., Ltd.

It runs as a scheduled task under the Windows Task Scheduler triggered to execute each time a user logs in.
Publisher:
PODCornCommunication. Co., Ltd.  (signed and verified)

Product:
autoexe

Version:
1.00.0002

MD5:
1d9f7a60fc071118af370c51d0b3ba63

SHA-1:
6986b3a1b7ba5e9ac3d30f90b09005ab15634e0d

SHA-256:
e8d43b96e637484f16da192528995a43f144c2ae161fb90552b0a2790f53ec32

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/23/2024 4:02:36 PM UTC  (today)

Scan engine
Detection
Engine version

IKARUS anti.virus
Worm.Win32.Vobfus
t3scan.2.0.6.0

File size:
506.6 KB (518,744 bytes)

Product version:
1.00.0002

Original file name:
autoexe.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\danpot\autoexe.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/23/2012 9:00:00 AM

Valid to:
11/24/2013 8:59:59 AM

Subject:
CN="PODCornCommunication. Co., Ltd.", OU=IT Team, O="PODCornCommunication. Co., Ltd.", L=Sungnam-si, S=Gyeonggi-do, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
6399E0A5FC1F7D0E257DEEA8F22D0BC9

File PE Metadata
Compilation timestamp:
1/15/2013 10:44:07 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:06n3ON2jUdDE/o8Mn6iLu04zmg2bWRYn3ON2jUdDE/o8Mn6iLu04zmg2P:xeN2eE/ojRReN2eE/ojR

Entry address:
0x1320

Entry point:
68, E0, C3, 43, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 38, 00, 00, 00, 00, 00, 00, 00, 4D, 3C, 84, 75, 2F, C6, 36, 45, 9E, 17, 03, AB, 95, 83, 76, 01, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 41, 75, 74, 6F, 45, 78, 65, 00, 00, 00, 00, 00, FF, CC, 31, 00, 15, 7B, A6, D3, 7D, 24, 00, B1, 46, 9C, F0, B4, 2C, ED, 28, A3, 5A, A6, 1E, 9C, EC, 5E, 26, E0, 4E, 8E, 69, 8D, C3, 04, D5, F7, 8A, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00, AA, 00, 60, D3, 93, 00, 00, 00...
 
[+]

Entropy:
4.2107

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
252 KB (258,048 bytes)

Scheduled Task
Task name:
PowerIEManager_Danpot

Trigger:
Logon (Runs on logon)


Scan autoexe.exe - Powered by Reason Core Security