PrivacyDr.exe

Privacy Dr

EuroTrade Ltd

The application PrivacyDr.exe by EuroTrade has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Publisher:
EuroTrade A.L. Ltd  (signed by EuroTrade Ltd)

Product:
Privacy Dr

Version:
3.0.3.0

MD5:
bce15074ad6edca3ecb5a7b1ddf7ff57

SHA-1:
3622a5275e83e0b1bf84c49d4515be9fb71a3eed

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/16/2024 4:55:14 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EuroTrade.RegClean.Optional.Meta (L)
15.11.12.18

File size:
4.9 MB (5,148,608 bytes)

Product version:
3.0.3.0

Copyright:
Copyright © 2015

Original file name:
PrivacyDr.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\privacy dr\privacydr.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/3/2015 4:00:00 PM

Valid to:
11/3/2020 3:59:59 PM

Subject:
CN=EuroTrade Ltd, O=EuroTrade Ltd, STREET=P.O box 2108, L=Hertzelia, S=non, PostalCode=46120, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
53DB4EF1BD09A69A8F5F557766365FE7

File PE Metadata
Compilation timestamp:
11/5/2015 1:04:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:+IoU5RksLnl3WmDaSzVUzY8pyXQg78+lBWa8D3+E0tK0:8sLnpWSh5UwXQMblBl8DnM

Entry address:
0x4CFB6E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.3548

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.8 MB (5,037,056 bytes)

Scheduled Task
Task name:
PrivacyDr_Popup

Path:
C:\WINDOWS\Tasks\PrivacyDr_Popup.job

Trigger:
Daily (Runs daily at 5:00 PM)

Description:
PrivacyDr_Popup


Remove PrivacyDr.exe - Powered by Reason Core Security