CryptoPrevent.exe

CryptoPrevent

Foolish IT LLC

It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time. This is installed with CryptoPrevent.
Publisher:
Foolish IT LLC  (signed and verified)

Product:
CryptoPrevent

Version:
7.03.0021

MD5:
6ef5f99c06f41e085dc96af9402a1a9e

SHA-1:
35ee9c34a535bf1c0f73006d629ababf241cc7d8

SHA-256:
fc46b1fb903332e093c03fd8f8889232f1605788134c69f2c4cf1306cf9db96b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 12:26:51 AM UTC  (today)

File size:
1.6 MB (1,694,864 bytes)

Product version:
7.03.0021

Copyright:
Foolish IT LLC

Original file name:
CryptoPrevent.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\foolish it\cryptoprevent\cryptoprevent.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
5/9/2014 11:38:40 PM

Valid to:
5/9/2016 7:34:08 PM

Subject:
E=foolishtech@foolishit.com, CN=Foolish IT LLC, O=Foolish IT LLC, L=Manteo, S=North Carolina, C=US, Description=D9J0KaT9DvjE2CWD

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
0E63

File PE Metadata
Compilation timestamp:
7/1/2015 6:19:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:a+UKSLwk4mjsGStGQQ00Iq7iQj2CTqax:a+sLwk4mgGStd6nKCT

Entry address:
0xDCD8

Entry point:
68, B8, E7, 40, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 8A, CE, DF, 66, EF, 9A, 5A, 42, 98, 80, 32, B2, AF, 42, A4, FD, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 43, 72, 79, 70, 74, 6F, 50, 72, 65, 76, 65, 6E, 74, 00, 00, 00, 00, 00, 00, 00, 01, 00, 1F, 00, C0, 07, 42, 00, 00, 00, 00, 00, FF, FF, FF, FF, FF, FF, FF, FF, 00, 00, 00, 00, E4, 0D, 42, 00, D4, 12, 52, 00, 00, 00, 00, 00, 68, 43, 1E, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2358

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
1.1 MB (1,179,648 bytes)

Scheduled Task
Task name:
CryptoPrevent Update

Trigger:
Daily (Runs daily at 3:58 AM)

Description:
Updates the CryptoPrevent application files and malware signature definitions from Foolish IT LLC (www.foolishit.com)


The file CryptoPrevent.exe has been discovered within the following programs.

CryptoPrevent  by Foolish IT, LLC
www.foolishit.com
About 3% of users remove it
 
Powered by Should I Remove It?

Scan CryptoPrevent.exe - Powered by Reason Core Security