PS.EXE

PS

Sergey Moskalev

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Punto Switcher’.
Publisher:
Punto.Ru  (signed by Sergey Moskalev)

Product:
PS

Description:
Punto Switcher

Version:
2, 9, 6, 0

MD5:
25a5e90796fd93241789e26537365bc0

SHA-1:
27aa913e7210e6eed95e6d7a13477b8614a37d46

SHA-256:
b8bc50c636b52b7a243ea37c1f204b07f7f99776e5527157c660642c5258277d

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 7:05:07 PM UTC  (today)

File size:
704.2 KB (721,088 bytes)

Product version:
2, 9, 6, 0

Copyright:
Punto.ru

Trademarks:
нет

Original file name:
PS.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\ps.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/31/2008 5:00:00 AM

Valid to:
4/1/2009 4:59:59 AM

Subject:
CN=Sergey Moskalev, OU=Punto, O=Sergey Moskalev, STREET=Bolshoy Kozikhinsky per. 23-36, L=Moscow, S=Moscow, PostalCode=123001, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B1CB2687F16C261F6F369A200825C00C

File PE Metadata
Compilation timestamp:
5/19/2008 6:12:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:+Lr76H2dpkveARVMOBSkEPp7mrGUxDDxwlApRlE:GWHdv1VDBSBPpyrGexwlApLE

Entry address:
0x385CA

Entry point:
E8, 4E, D8, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, C7, D8, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 45, 08, D1, F8, 48, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 55, 08, 53, 56, 57, 33, FF, 3B, D7, 74, 07, 8B, 5D, 0C, 3B, DF, 77, 1E, E8, 56, 02, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 38, 55, 00, 00, 83, C4, 14, 8B, C6, 5F, 5E, 5B, 5D, C3, 8B, 75, 10, 3B, F7, 75, 07, 33, C0...
 
[+]

Code size:
318.5 KB (326,144 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Punto Switcher

Command:
C:\Program Files\punto switcher\ps.exe


Scan PS.EXE - Powered by Reason Core Security