dcpp.exe

DriveCrypt Plus Pack

SecurStar GmbH

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Dcpp Startup’.
Publisher:
SecurStar GmbH  (signed and verified)

Product:
DriveCrypt Plus Pack

Description:
DriveCrypt Plus Pack GUI

Version:
1, 0, 0, 2

MD5:
8debef78ff562da71b78abd44b16817d

SHA-1:
e1621d1ff8fed446381cb68eba1a6b3a628208f4

SHA-256:
2bfcaed3b14a697b2fac58be7b6aacf1844b09861783890b0cbaf6f24ac73a00

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 11:02:01 AM UTC  (today)

File size:
2.3 MB (2,386,816 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright © 2002 - 2003 SecurStar GmbH

Original file name:
dcpp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\securstar\client\dcpp\dcpp.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
2/19/2010 12:37:28 PM

Valid to:
2/19/2013 12:37:23 PM

Subject:
CN=SecurStar GmbH, O=SecurStar GmbH, L=Munich, S=Germany, C=DE

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
01000000000126E62191BA

File PE Metadata
Compilation timestamp:
3/26/2010 2:07:27 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

Entry address:
0x4B4000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB...
 
[+]

Packer / compiler:
ASPack v1.08.04

Code size:
444 KB (454,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Dcpp Startup

Command:
"C:\Program Files\securstar\client\dcpp\dcpp.exe" \al


Scan dcpp.exe - Powered by Reason Core Security