Defender.exe

Telekom Dialerschutz-Software

Deutsche Telekom AG

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Telekom Dialerschutz-Software’.
Publisher:
Telekom Deutschland GmbH  (signed by Deutsche Telekom AG)

Product:
Telekom Dialerschutz-Software

Version:
2.8.12505.1

MD5:
2693a7aa66b21972bf28253eb3251248

SHA-1:
8d4b9a0b2bebad00c956d9ff3f0313c1c0e9a86d

SHA-256:
7cfaddef37feb6d419c80ace57f8623767a9af6079d80f52d835fb4185c3446f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/20/2024 4:02:52 AM UTC  (today)

File size:
3.2 MB (3,332,536 bytes)

Product version:
2.8.12505.1

Copyright:
© Telekom Deutschland GmbH, 2012, TK

Original file name:
Defender.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\telekom\dialerschutz-software\defender.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/23/2012 1:00:00 AM

Valid to:
11/24/2014 12:59:59 AM

Subject:
CN=Deutsche Telekom AG, OU=Digital ID Class 3 - Microsoft Software Validation v2, OU=Access Services, O=Deutsche Telekom AG, L=Darmstadt, S=Hessen, C=DE

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
42224CA040519993F071DC42EA1C0FAF

File PE Metadata
Compilation timestamp:
12/14/2012 8:54:32 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
98304:Lljmk13b//UsHE2g9z0VnAE9Y2UL0+FdYyeXgqxcSgmLfaFwpuoyXEv6jyAa:hjmk6V0b9VWyvpuoyXs6OJ

Entry address:
0x1F1813

Entry point:
E8, 50, 38, 01, 00, E9, 89, FE, FF, FF, CC, CC, CC, 8B, 4C, 24, 0C, 57, 85, C9, 0F, 84, B7, 00, 00, 00, 8B, 7C, 24, 08, 56, F7, C7, 03, 00, 00, 00, 53, 74, 11, 8A, 07, 83, C7, 01, 84, C0, 74, 39, F7, C7, 03, 00, 00, 00, 75, EF, 8B, 07, BA, FF, FE, FE, 7E, 03, D0, 83, F0, FF, 33, C2, 83, C7, 04, A9, 00, 01, 01, 81, 74, E8, 8B, 47, FC, 84, C0, 74, 21, 84, E4, 74, 18, A9, 00, 00, FF, 00, 74, 0C, A9, 00, 00, 00, FF, 75, CF, 83, EF, 01, EB, 0D, 83, EF, 02, EB, 08, 83, EF, 03, EB, 03, 83, EF, 04, 8B, 74, 24, 14...
 
[+]

Code size:
2.3 MB (2,360,320 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Telekom Dialerschutz-Software

Command:
"C:\Program Files\telekom\dialerschutz-software\defender.exe"


Scan Defender.exe - Powered by Reason Core Security