deobfuscatorwin32.exe

dotNet Protector

PV Logiciels

The executable deobfuscatorwin32.exe has been detected as malware by 1 anti-virus scanner.
Publisher:
PV Logiciels  (signed and verified)

Product:
dotNet Protector™

Description:
dotNet Protector

Version:
1.0.3240.27928

MD5:
af2acebc46d2cf4b930dcc2b16ffd343

SHA-1:
d790c235685b6d6ba61d69b5ce4e90b9db2bb4a4

SHA-256:
ed0a19dccf5da79c6cd49448b910d72119caf6634657ec8e73a9df8c5954acd2

Scanner detections:
1 / 68

Status:
Malware

Analysis date:
4/26/2024 3:26:34 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Threat.Win.Reputation.IMP
16.9.18.8

File size:
669.3 KB (685,312 bytes)

Product version:
1.0.3240.27928

Copyright:
Copyright © 2006-2008, PV Logiciels

Trademarks:
dotNet Protector™

Original file name:
DeObfuscator.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\pv logiciels\dotnet tools x64\deobfuscatorwin32.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/7/2006 5:00:00 PM

Valid to:
11/7/2009 4:59:59 PM

Subject:
CN=PV Logiciels, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=PV Logiciels, L=LA TESSOUALLE, S=Maine et Loire, C=FR

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
797B0B74E3E1F72E05C48BB496D5861F

File PE Metadata
Compilation timestamp:
11/14/2008 7:18:04 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:2A8KOY5RgPpKSCzIMC1krsTvio4sV0Xf7/hek7VJe6fGyzxtCMg7XpPW3Y:9gBApC1G9GyiMiUI

Entry address:
0x89FDC

Entry point:
FF, 25, 3C, B3, 48, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 08, 8D, 42, 0C, 8B, 4A, EC, 33, C8, E8, D7, 09, FD, FF, B8, 68, E3, 49, 00, E9, AD, 1F, FD, FF, CC, CC, CC, CC, CC, B8, F0, E4, 49, 00, E9, 9E, 1F, FD, FF, CC, CC, CC, CC, CC, CC, B8, 48, E5, 49, 00, E9, 8E, 1F, FD, FF, CC, CC, CC, CC, CC, CC, B8, A0, E5, 49, 00, E9, 7E, 1F, FD, FF, CC, CC, CC, CC, CC, CC, B8, F8, E5, 49, 00, E9, 6E, 1F, FD, FF, CC, CC, CC, CC, CC, CC, B8, 50, E6, 49, 00, E9, 5E, 1F, FD, FF, CC, CC...
 
[+]

Entropy:
7.3133

Code size:
552 KB (565,248 bytes)

Remove deobfuscatorwin32.exe - Powered by Reason Core Security