psr.exe

Password Safe and Repository 6

MATESO GmbH

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Password Safe Enterprise’. This file is installed with the program Password Safe and Repository 6.
Publisher:
MATESO GmbH  (signed and verified)

Product:
Password Safe and Repository 6

Version:
6.4.1.2155

MD5:
95f6f3fea654a6ce28c087f9776332cf

SHA-1:
00fd58ffd969409c72cc950472a455d0348c43ff

SHA-256:
d82116a7a22506a2cadbcfa85e7c109c4368a2f6093ddd1e55de58b80970c22c

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/20/2024 1:39:25 AM UTC  (today)

Scan engine
Detection
Engine version

Trend Micro House Call
TROJ_GEN.F47V0218
7.2.146

File size:
4.7 MB (4,906,040 bytes)

Product version:
6.4.1.2155

Copyright:
© 2001-2011 MATESO GmbH

Original file name:
psr.exe

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
6/22/2011 2:00:00 AM

Valid to:
7/2/2012 1:59:59 AM

Subject:
CN=MATESO GmbH, OU=SECURE APPLICATION DEVELOPMENT, O=MATESO GmbH, L=Gersthofen, S=Bayern, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
5430DDAE168AD7DB0CF9863C62FC308E

File PE Metadata
Compilation timestamp:
5/2/2012 11:44:06 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:Z+mxigX2MUmoaWre2+zHlbNncaMfXtFgUE77gKgjARZ2zPISgdYfPaxqguwLgABa:Z+227mcrR+zFJcz/Xg77gKea2cSgqfPB

Entry address:
0x125D001

Entry point:
60, E8, 03, 00, 00, 00, E9, EB, 04, 5D, 45, 55, C3, E8, 01, 00, 00, 00, EB, 5D, BB, ED, FF, FF, FF, 03, DD, 81, EB, 00, D0, 25, 01, 83, BD, 88, 04, 00, 00, 00, 89, 9D, 88, 04, 00, 00, 0F, 85, CB, 03, 00, 00, 8D, 85, 94, 04, 00, 00, 50, FF, 95, A9, 0F, 00, 00, 89, 85, 8C, 04, 00, 00, 8B, F0, 8D, 7D, 51, 57, 56, FF, 95, A5, 0F, 00, 00, AB, B0, 00, AE, 75, FD, 38, 07, 75, EE, 8D, 45, 7A, FF, E0, 56, 69, 72, 74, 75, 61, 6C, 41, 6C, 6C, 6F, 63, 00, 56, 69, 72, 74, 75, 61, 6C, 46, 72, 65, 65, 00, 56, 69, 72, 74...
 
[+]

Packer / compiler:
ASPack v2.12

Code size:
8.6 MB (9,019,904 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Password Safe Enterprise

Command:
\unity\data\passwordsafe\psr.exe


The file psr.exe has been discovered within the following program.

www.passwordsafe.de
1% remove it
 
Powered by Should I Remove It?

Scan psr.exe - Powered by Reason Core Security