PrivacyDr.exe

Privacy Dr

EuroTrade Ltd

The application PrivacyDr.exe by EuroTrade has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a scheduled task under the Windows Task Scheduler triggered daily at a specified time.
Publisher:
EuroTrade A.L. Ltd  (signed by EuroTrade Ltd)

Product:
Privacy Dr

Version:
3.1.2.0

MD5:
651908d0a7c5d2dce4c71bd628417b51

SHA-1:
3f207a531e0791b3bff71316c6666ae4b67da490

SHA-256:
76c7117b73a9b87cdd300bc798357256a4b90945e65f298e17bf09d7aea02052

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
5/16/2024 6:57:28 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.EuroTrade.RegClean.Optional.Meta (L)
16.2.24.19

File size:
4.8 MB (5,004,272 bytes)

Product version:
3.1.2.0

Copyright:
Copyright © 2015

Original file name:
PrivacyDr.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\privacy dr\privacydr.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/3/2015 7:00:00 PM

Valid to:
11/3/2020 6:59:59 PM

Subject:
CN=EuroTrade Ltd, O=EuroTrade Ltd, STREET=P.O box 2108, L=Hertzelia, S=non, PostalCode=46120, C=IL

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
53DB4EF1BD09A69A8F5F557766365FE7

File PE Metadata
Compilation timestamp:
1/18/2016 6:28:37 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
49152:vCSHCXRksLnl3WmDaSzVULXmpyXQfL8+uBWa8D3ATE0D:OmsLnpWSh5UVXQzbuBl8Dc

Entry address:
0x4AD1A6

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D0, 4A, 00, 0C, 00, 00, 00, A8, 31, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.7282

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
4.7 MB (4,895,232 bytes)

Scheduled Task
Task name:
PrivacyDr_Popup

Trigger:
Daily (Runs daily at 3:15 PM)

Description:
PrivacyDr_Popup


Remove PrivacyDr.exe - Powered by Reason Core Security