PPDrive.exe

Pogoplug

Cloud Engines, Inc

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Pogoplug’. This is installed with Pogoplug.
Scan PPDrive.exe - Powered by Reason Core Security
Publisher:
CloudEngines  (signed by Cloud Engines, Inc)

Product:
Pogoplug

Description:
Pogoplug Drive

Version:
3.1.0.0

MD5:
376b8cd07ebcad756117c74cf27e71c5

SHA-1:
62e4358e305f9000a7b1c2d1df046e0257c2de33

SHA-256:
ce63724ff0c87ea81224bba79b33c825a0354454e253b646aed9ef0799a071e4

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/3/2016 6:51:24 PM UTC  (today)

File size:
248.8 KB (254,784 bytes)

Product version:
3.1.0.0

Copyright:
Copyright © CloudEngines 2011

Original file name:
PPDrive.exe

File type:
Executable application (Win64 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\pogoplug\ppdrive.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/12/2011 8:00:00 PM

Valid to:
6/22/2014 7:59:59 PM

Subject:
CN="Cloud Engines, Inc", OU=Pogoplug, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Cloud Engines, Inc", L=San Francisco, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
0D58B379078D4CFC02E6313E5D94628A

File PE Metadata
Compilation timestamp:
6/21/2011 4:15:06 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
3072:RcR32wV322P2f/eWAR8SwZPeKna91ixom4AGbeoN89dOKHyTyETw32K:RcfFFWgw5JAAGtN89fF

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 80, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.6110

Code size:
216 KB (221,184 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Pogoplug

Command:
"C:\Program Files\pogoplug\ppdrive.exe"


The file PPDrive.exe has been discovered within the following program.

Pogoplug  by Cloud Engines Inc.
Publisher's description - “Leave your computer at home or the office but quickly access and download all of your files from any Web browser, smartphone or tablet. Share large files and folders instantly, without uploading.”
www.pogoplug.com
About 5% of users remove it
 
Powered by Should I Remove It?

Scan PPDrive.exe - Powered by Reason Core Security