mcshieldds.exe

MCShield ::Anti-Malware Tool::

Borislav Surbat

This is installed with MCShield ::Anti-Malware Tool::.
Publisher:
MyCity  (signed by Borislav Surbat)

Product:
MCShield ::Anti-Malware Tool::

Description:
MCShield Drive Scanner

Version:
3.0.3.41

MD5:
37961005a8b452603b7503db3de33e50

SHA-1:
a26f2e14ce1463a656487f3975f9d6102978fa24

SHA-256:
a7fe5ba64b6b3811bf43c330d14818d960d5ddf1f08f60943b8e7ab682d33b5b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/16/2024 4:42:07 PM UTC  (today)

File size:
407.6 KB (417,344 bytes)

Product version:
3.0.3.26

Copyright:
© MyCity

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\mcshield\mcshieldds.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
1/20/2014 1:00:00 AM

Valid to:
1/21/2015 12:59:59 AM

Subject:
CN=Borislav Surbat, O=Borislav Surbat, STREET=Storgatan 53, L=Hoganas, S=Skane, PostalCode=26331, C=SE

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00F18CA38A8EBE51655C3D5EC4676A5C3A

File PE Metadata
Compilation timestamp:
2/5/2013 12:06:48 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:FHT33KP4gbJzT6+Jylc0eJxlO4+QaGxmDIxI:FDKPPJH6GOc04x44+Gx0IxI

Entry address:
0x274E8

Entry point:
55, 8B, EC, 83, C4, E4, 53, 56, 57, 33, C0, 89, 45, E4, 89, 45, EC, 89, 45, E8, B8, BC, 6D, 42, 00, E8, 8E, F7, FD, FF, 33, C0, 55, 68, 77, 77, 42, 00, 64, FF, 30, 64, 89, 20, 33, C0, A3, CC, EA, 42, 00, A1, 54, 8C, 42, 00, 33, D2, 89, 10, B3, 01, 33, C0, 55, 68, 5E, 75, 42, 00, 64, FF, 30, 64, 89, 20, 68, 90, 77, 42, 00, 6A, 0A, 8B, 0D, 2C, 8D, 42, 00, 8B, 09, B2, 01, A1, 58, 67, 41, 00, E8, C1, 20, FF, FF, A3, CC, EA, 42, 00, 33, C0, 5A, 59, 59, 64, 89, 10, EB, 16, E9, 11, CB, FD, FF, 33, DB, A1, CC, EA...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
154 KB (157,696 bytes)

The file mcshieldds.exe has been discovered within the following program.

mailto: MCShield@MyCity.rs
About 1% of users remove it
 
Powered by Should I Remove It?

Scan mcshieldds.exe - Powered by Reason Core Security