PS.EXE

PS

Sergey Moskalev

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Punto Switcher’.
Publisher:
Punto.Ru  (signed by Sergey Moskalev)

Product:
PS

Description:
Punto Switcher

Version:
2, 9, 6, 3

MD5:
a7854b12f9329ccf5011fa115b120e6c

SHA-1:
4584280b9092034fddaad2d8d663bf0846344f26

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 3:39:47 AM UTC  (today)

File size:
705.2 KB (722,112 bytes)

Product version:
2, 9, 6, 3

Copyright:
Punto.ru

Trademarks:
нет

Original file name:
PS.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\punto switcher\ps.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/31/2008 5:30:00 AM

Valid to:
4/1/2009 5:29:59 AM

Subject:
CN=Sergey Moskalev, OU=Punto, O=Sergey Moskalev, STREET=Bolshoy Kozikhinsky per. 23-36, L=Moscow, S=Moscow, PostalCode=123001, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B1CB2687F16C261F6F369A200825C00C

File PE Metadata
Compilation timestamp:
5/30/2008 6:40:37 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:CclE3FRY7Aoh4OW6wJY851sUTW4LN+8+cKe0lApRS:dQFe7dhgFrsT4Lk8+5lApg

Entry address:
0x3873A

Entry point:
E8, 4E, D8, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, C7, D8, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 45, 08, D1, F8, 48, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 55, 08, 53, 56, 57, 33, FF, 3B, D7, 74, 07, 8B, 5D, 0C, 3B, DF, 77, 1E, E8, 56, 02, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, 38, 55, 00, 00, 83, C4, 14, 8B, C6, 5F, 5E, 5B, 5D, C3, 8B, 75, 10, 3B, F7, 75, 07, 33, C0...
 
[+]

Code size:
319 KB (326,656 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Punto Switcher

Command:
C:\Program Files\punto switcher\ps.exe


Scan PS.EXE - Powered by Reason Core Security