Folder Protect.exe

Folder Protect

NewSoftwares.net Inc. SDN. BHD.

The application Folder Protect.exe, “Security Data Software” by NewSoftwares.net SDN. BHD has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Newsoftwares.net, Inc  (signed by NewSoftwares.net Inc. SDN. BHD.)

Product:
Folder Protect

Description:
Security Data Software

Version:
1.7.0.0

MD5:
b43a91609fe4cbdadee137da11aa4b8b

SHA-1:
be0c26bc74cce96c6213629a0c5ba2f516e83def

SHA-256:
04349332f1fc2d10e616cfa2424c22e427f767988359be7710ce4578fb86a445

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/27/2024 2:52:29 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.NewSoftwaresnetSDNBHD
16.1.18.15

File size:
8.1 MB (8,527,952 bytes)

Product version:
1.7.0.0

Trademarks:
Folder Protect

Original file name:
Folder Protect.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\folder protect\folder protect.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
2/3/2009 4:23:54 PM

Valid to:
2/3/2012 4:23:54 PM

Subject:
E=president@newsoftwares.net, CN=NewSoftwares.net Inc. SDN. BHD., O=NewSoftwares.net Inc. SDN. BHD., C=MY

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000011F3BFCD88E

File PE Metadata
Compilation timestamp:
3/16/2010 4:25:19 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
49152:ruHGrXJmuPijKRq41sATiVvMbdd4dddXw9gI9JSEPAgV:3zXftsATiVv0dd4dddXwl9oEdV

Entry address:
0x820253

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, 68, 00, A9, 5E, 1F, 38, BC, EF, AD, 39, B4, F3, 2A, 07, 95, 1B, D4, BB, 28, 6F, 8B, 05, 72, 71, EE, 32, 53, FD, A7, 27, 1D, 24, FD, 55, 92, 56, 24, 6E, 87, 76, 88, C6, 94, 16, 79, 5E, BB, 8D, FE, AB, 32, 8C, 18, EC, BB, 40, FE, AB, 32, 8C, 18, EC, BB, 40, E9, C9, 4B, 00, 00, E9, DD, 4B, 00, 00, E9, D8, 4B, 00, 00, E8, 5E, FB, FF, FF, 4E, DD, 00, 00, 4C, 8F, 00, 00, 61, C0, 0C, D4, C1, 3F, 41, 63, 7A, 17, D4, 9C, 6C, BB, 71, 50, 70, 09, 70, 13, 7F, 93, 49, 2F, 35...
 
[+]

Entropy:
5.6213

Packer / compiler:
MoleBox v2.0

Remove Folder Protect.exe - Powered by Reason Core Security