PS.EXE

PS

Sergey Moskalev

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Punto Switcher’.
Publisher:
Punto.Ru  (signed by Sergey Moskalev)

Product:
PS

Description:
Punto Switcher

Version:
2, 9, 6, 0

MD5:
5ab36831fb413f5ba7249917d36994fc

SHA-1:
cb9bba4ae1e8ef01a30d42da2655566adadf3694

SHA-256:
861936db8806a2fe0d84c0c996dacf9fe8bbcacb8649693ff36d6c501a0c6e30

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 6:03:11 AM UTC  (today)

File size:
702.2 KB (719,040 bytes)

Product version:
2, 9, 6, 0

Copyright:
Punto.ru

Trademarks:
нет

Original file name:
PS.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\punto switcher\ps.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/31/2008 3:00:00 AM

Valid to:
4/1/2009 2:59:59 AM

Subject:
CN=Sergey Moskalev, OU=Punto, O=Sergey Moskalev, STREET=Bolshoy Kozikhinsky per. 23-36, L=Moscow, S=Moscow, PostalCode=123001, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
00B1CB2687F16C261F6F369A200825C00C

File PE Metadata
Compilation timestamp:
5/14/2008 2:22:50 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:cOx7tIReGvVeVM823sugCfjhMGrAccg6CAvGDVyZlApRl9:rCRHMYng66sAccCAv8yZlApL9

Entry address:
0x382F7

Entry point:
E8, 86, D8, 00, 00, E9, 78, FE, FF, FF, 8B, FF, 55, 8B, EC, 6A, 00, FF, 75, 14, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, FF, D8, 00, 00, 83, C4, 14, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 45, 08, 66, 8B, 08, 40, 40, 66, 85, C9, 75, F6, 2B, 45, 08, D1, F8, 48, 5D, C3, 8B, FF, 55, 8B, EC, 8B, 55, 08, 53, 56, 57, 33, FF, 3B, D7, 74, 07, 8B, 5D, 0C, 3B, DF, 77, 1E, E8, 59, 02, 00, 00, 6A, 16, 5E, 89, 30, 57, 57, 57, 57, 57, E8, EB, 52, 00, 00, 83, C4, 14, 8B, C6, 5F, 5E, 5B, 5D, C3, 8B, 75, 10, 3B, F7, 75, 07, 33, C0...
 
[+]

Code size:
317 KB (324,608 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Punto Switcher

Command:
C:\Program Files\punto switcher\ps.exe


Scan PS.EXE - Powered by Reason Core Security