ptservice.exe

USB Block

NewSoftwares.net, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DBPrompt’.
Publisher:
NewSoftwares.net, Inc.

Product:
USB Block

Description:
USB-Block Application

Version:
1.5.0.0

MD5:
610222582b47f3a093e1a7c4482f82e9

SHA-1:
1bc7b721aabb31f92200cc2fd2166f502dabd5da

SHA-256:
1bcda83ea4444ece19f09c0b520b4a2575b6c7c51a2d1d3394dc59d8b760ddc8

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
1/1/2026 2:53:42 PM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
HW32.CDB
1.3.0.4923

Comodo Security
UnclassifiedMalware
17716

File size:
307.4 KB (314,731 bytes)

Product version:
1.5.0.0

Copyright:
Copyright © 1998-2012 NewSoftwares.net, Inc. All Rights Reserved.

Original file name:
PromptService.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\windows\ptservice.exe

File PE Metadata
Compilation timestamp:
1/13/2012 2:35:15 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:G881YYARMwomlTFfgNeo6PmiImdmWZkDTrjJoOGsp3mZPfJW:m9A6w3l5oNh6wy7ZU3lmscVfg

Entry address:
0x47B33

Entry point:
E8, 00, 00, 00, 00, 60, E8, 4F, 00, 00, 00, 46, BD, A8, 13, 2A, 9E, 66, E4, ED, 72, B7, 97, 8E, 02, 19, 4E, D2, 3B, 24, FA, 70, D2, 0E, 5C, 89, DC, E6, B2, 08, 88, 20, 45, 55, 66, 2A, 46, E4, 94, DE, 19, 84, 68, 43, E7, 5C, F2, 4B, FD, EF, 8C, E2, F6, AC, 50, 56, B8, EF, 8C, E2, F6, AC, 50, 56, B8, E9, 1A, 6D, 00, 00, E9, 2E, 6D, 00, 00, E9, 29, 6D, 00, 00, E8, 6E, FB, FF, FF, 6E, 00, 01, 00, 05, 99, 00, 00, 57, 4F, 39, C5, 18, 73, D1, 06, 0C, 39, 74, 46, D5, 43, 91, FF, 58, F3, D0, 0D, 78, 9F, 69, 15, E9...
 
[+]

Packer / compiler:
MoleBox v2.0

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DBPrompt

Command:
"C:\windows\ptservice.exe"


Scan ptservice.exe - Powered by Reason Core Security