protectfolder.exe

Everstrike Folder Crypto Password

Everstrike OOO

The application protectfolder.exe, “Folder Crypto Password” by Everstrike OOO has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Everstrike Software  (signed by Everstrike OOO)

Product:
Everstrike Folder Crypto Password

Description:
Folder Crypto Password

Version:
3, 2, 1, 0

MD5:
571fe5fcd578d555340961e490198ceb

SHA-1:
fea2cc8f7e8889e7a087c1e6a7b2146efaeab928

SHA-256:
d88ae0fdab331ef42fd7c8d45425fc59aa8886edd75c455c5728eb1cd247df3e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/25/2024 11:46:21 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Everstrike (M)
16.2.11.1

File size:
3.9 MB (4,043,392 bytes)

Product version:
3, 2, 1, 0

Copyright:
Copyright © 2010

Original file name:
FCP.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\protect folder\protectfolder.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
1/21/2010 7:00:00 AM

Valid to:
1/14/2011 6:59:59 AM

Subject:
CN=Everstrike OOO, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Everstrike OOO, L=Ulyanovsk, S=n/a, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
4F047BCF18A6FDD97F5D03D2A61289D8

File PE Metadata
Compilation timestamp:
8/16/2010 5:39:18 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:vej6CmLn1HLsZSgGtncjSn5eZ9iQybJN0840lqw4:vFRT9LWqnoSnIzgbJnlAz

Entry address:
0xC587DC

Entry point:
E9, 1A, 43, E0, FF, 35, 1C, D4, 7C, CF, AF, BF, C3, 01, 95, 6D, E6, 59, 4E, F5, CA, 09, 1C, A2, 93, 9D, A2, B7, 99, 43, 32, D1, C1, 6B, 0A, C9, F8, 40, 3F, 62, D0, 21, E0, 82, 51, 4E, D4, 41, BF, 35, 66, D4, 94, F5, 36, 06, ED, 2F, 3B, 7D, A5, 91, 80, F1, B6, F7, 71, 33, 2F, D3, 7D, 33, 98, DB, 57, 8C, 6B, B5, 03, 2F, AC, 97, 03, 2C, 94, B2, 25, B7, 05, B2, EC, B7, 5E, 59, CB, C9, BE, D5, 04, C4, 4B, 2F, AC, A7, B4, A0, 6B, 75, 56, 22, 3D, 2F, 7A, A7, 42, 96, 20, 9C, D4, 09, BA, 31, 59, A9, 5C, 83, 81, 80...
 
[+]

Entropy:
7.9404

Packer / compiler:
Xtreme-Protector v1.05

Code size:
13.5 MB (14,176,768 bytes)

Remove protectfolder.exe - Powered by Reason Core Security