PCClient.exe

Policy Central Enterprise

Forensic Software Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PCE Client’.
Publisher:
Forensic Software Ltd  (signed by Forensic Software Limited)

Product:
Policy Central Enterprise

Description:
PCClient

Version:
5.1.4.6

MD5:
25e797e0f4087ffa0e38963da063fe3d

SHA-1:
ff9e8ad1cb2a4e101b9719f45ed33108dbb41af3

SHA-256:
fb5ddcf2f06b789fedabe35128742840e55daec3f724001b13e2c5022718e83e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/28/2024 12:59:25 PM UTC  (today)

File size:
4.2 MB (4,368,136 bytes)

Product version:
5.1.4.6

Copyright:
Forensic Software Ltd © 2010

Original file name:
PCClient.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pcent\pcclient.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
10/5/2012 1:00:00 AM

Valid to:
12/9/2013 12:00:00 PM

Subject:
CN=Forensic Software Limited, O=Forensic Software Limited, L=Windsor, C=GB

Issuer:
CN=DigiCert High Assurance Code Signing CA-1, OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
095E9C7DD190B2FC06392E0C254D5E35

File PE Metadata
Compilation timestamp:
2/6/2013 6:30:29 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:C6zC291Fr/rm9/M35lGzE7qdIX/YGKKGBEPMOwkiKvLy5FK:Td/mKjGz/BEP1zy5FK

Entry address:
0x1D79D0

Entry point:
48, 83, EC, 28, E8, E7, A2, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 85, C9, 74, 37, 53, 48, 83, EC, 20, 4C, 8B, C1, 48, 8B, 0D, E8, 2A, 19, 00, 33, D2, FF, 15, F0, 8B, 03, 00, 85, C0, 75, 17, E8, 9B, 57, 00, 00, 48, 8B, D8, FF, 15, 46, 91, 03, 00, 8B, C8, E8, 43, 57, 00, 00, 89, 03, 48, 83, C4, 20, 5B, C3, CC, CC, CC, 40, 53, 48, 83, EC, 20, 45, 8B, 18, 48, 8B, DA, 4C, 8B, C9, 41, 83, E3, F8, 41, F6, 00, 04, 4C, 8B, D1, 74, 13, 41, 8B, 40, 08, 4D, 63, 50, 04, F7, D8, 4C, 03, D1, 48, 63, C8...
 
[+]

Entropy:
5.5445

Code size:
2.1 MB (2,155,520 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PCE Client

Command:
"C:\Program Files\pcent\pcclient.exe"


Scan PCClient.exe - Powered by Reason Core Security