MaxProtector32.sys

Max Secure Software Startup Manager Driver

Max Secure Software India Pvt. Ltd.

The file MaxProtector32.sys by Max Secure Software India Pvt has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Max Secure Software  (signed by Max Secure Software India Pvt. Ltd.)

Product:
Max Secure Software Startup Manager Driver

Version:
2, 0, 0, 3

MD5:
d16e1dd8a2c7aa73c44bac9df5abfec9

SHA-1:
b6ac7c9ea9ca04e70412eba133e8d31615c844d5

SHA-256:
e14d2cc15402c1c9b190bc96c2289b929f1d4285985c95cd47836df10359a80c

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/16/2024 10:00:56 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.MaxSecure.Optional.Meta (L)
16.2.14.11

File size:
84 KB (85,984 bytes)

Product version:
19, 0, 1, 4

Copyright:
(c) Max Secure Software. All rights reserved.

Trademarks:
Max Secure Software

Original file name:
MaxProtector32.sys

File type:
Driver (Win32 SYS)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\maxprotector32.sys

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
4/3/2012 2:00:08 AM

Valid to:
7/24/2014 10:57:41 AM

Subject:
E=tech@maxpcsecure.com, CN=Max Secure Software India Pvt. Ltd., O=Max Secure Software India Pvt. Ltd., L=pune, S=MH, C=IN

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11216A69882C6D7835A9F4F1D6DCB7AC9C32

File PE Metadata
Compilation timestamp:
2/13/2014 1:41:57 PM

OS version:
6.1

OS bitness:
Win32

Subsystem:
Native (none required)

Linker version:
9.0

CTPH (ssdeep):
1536:WD5DcjyadTZlSDyHVQhKl4f/vvfvf/vvf3L7/skPPv/nH/vPvfPvMff/f/PP2sDv:WD5DAyadVlSDyHVQhKl4f/vvfvf/vvfm

Entry address:
0x1403E

Entry point:
8B, FF, 55, 8B, EC, E8, BD, FF, FF, FF, 5D, E9, 60, EE, FE, FF, CC, CC, 9C, 40, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, DE, 44, 01, 00, 10, 50, 00, 00, 8C, 40, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 45, 01, 00, 00, 50, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 0C, 45, 01, 00, F8, 44, 01, 00, 1A, 45, 01, 00, 00, 00, 00, 00, FA, 41, 01, 00, 04, 42, 01, 00, 1C, 42, 01, 00, 38, 42, 01, 00, 52, 42, 01, 00, 6C, 42, 01, 00, 88, 42, 01, 00, A0, 42, 01, 00, B4, 42...
 
[+]

Entropy:
5.3585

Code size:
22.5 KB (23,040 bytes)

Remove MaxProtector32.sys - Powered by Reason Core Security