PnPDetect.EXE

PnPDetect Application

Newsoft Technology Company

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Smart Start UP’.
Publisher:
NewSoft Technology Corporation  (signed by Newsoft Technology Company)

Product:
PnPDetect Application

Description:
PnPDetect MFC Application

Version:
1, 0, 0, 1

MD5:
0f2ade9838cc2c370c7f60400533f54c

SHA-1:
fb61eb9ce1ccfeae1cf92b20c840259b5dc2cc18

SHA-256:
aeeb194aed695c4a7392bca9227f66443de7a1ed0a514c2690e110c1375195b1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 4:24:05 PM UTC  (today)

File size:
178.5 KB (182,807 bytes)

Product version:
1, 0, 0, 1

Copyright:
NewSoft Technology Corporation, All Rights Reserved.

Original file name:
PnPDetect.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\newsoft\smart start up\pnpdetect.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/25/2006 6:00:00 AM

Valid to:
5/6/2007 5:59:59 AM

Subject:
CN=Newsoft Technology Company, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Newsoft Technology Company, L=Hsinchu, S=Hsinchu, C=TW

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6305022C11FDFBAAE1DE47B3DABA95A8

File PE Metadata
Compilation timestamp:
11/21/2006 2:23:30 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x1071E

Entry point:
E9, A7, BA, FF, FF, 68, 78, 1D, 41, 00, 68, F8, 08, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 68, 53, 56, 57, 89, 65, E8, 33, DB, 89, 5D, FC, 6A, 02, FF, 15, A0, 13, 41, 00, 59, 83, 0D, 98, 50, 41, 00, FF, 83, 0D, 9C, 50, 41, 00, FF, FF, 15, 34, 14, 41, 00, 8B, 0D, 8C, 50, 41, 00, 89, 08, FF, 15, B0, 13, 41, 00, 8B, 0D, 88, 50, 41, 00, 89, 08, A1, B4, 13, 41, 00, 8B, 00, A3, 94, 50, 41, 00, E8, 6A, 01, 00, 00, 39, 1D, E0, 47, 41, 00, 75, 0C, 68, F4, 08, 41, 00, FF, 15, B8, 13...
 
[+]

Entropy:
7.0752

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
64 KB (65,536 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Smart Start UP

Command:
C:\Program Files\newsoft\smart start up\pnpdetect.exe \automation


Scan PnPDetect.EXE - Powered by Reason Core Security