PWRISOVM.EXE

PowerISO Virtual Drive Manager

Power Software Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘PWRISOVM.EXE’.
Publisher:
Power Software Ltd  (signed by Power Software Limited)

Product:
PowerISO Virtual Drive Manager

Version:
6, 1, 0, 0

MD5:
3de586ff547421fcc287bd26832a9f4a

SHA-1:
74d663252999d0b30a76902535a39f51d9f9efcf

SHA-256:
932995ec24c47972ac26fb5474c1f360a790a0db183e46376e575c555ab7723f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

False Positives:
A number of engines detected this file but were erroneous detections (false positives).

Analysis date:
4/19/2024 12:55:53 AM UTC  (today)

File size:
399.3 KB (408,888 bytes)

Product version:
6, 1, 0, 0

Copyright:
Copyright (C) 2004-2014

Original file name:
PWRISOVM.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\Program Files\poweriso\pwrisovm.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/26/2014 5:00:00 PM

Valid to:
6/25/2017 4:59:59 PM

Subject:
CN=Power Software Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Power Software Limited, L=Hong Kong, S=Hong Kong, C=HK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
227EFDF22825BA270530FB09D52B32F8

File PE Metadata
Compilation timestamp:
10/8/2014 6:00:46 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
6144:hAZY7KZN+n0wT8pXaXQ5LuHQofNjPghByKMIVIa/HbrbfPFJJJ:hAZ22NA0q8p18JNLghBXcGHb/ftJ7

Entry address:
0xB1C0

Entry point:
48, 8B, C4, 48, 81, EC, A8, 00, 00, 00, 48, 89, 58, 18, 48, 89, 78, 20, 48, 8D, 48, 88, FF, 15, 84, 92, 01, 00, FF, 15, 76, 92, 01, 00, 48, 8B, C8, 33, D2, 41, B8, 94, 00, 00, 00, FF, 15, 5D, 92, 01, 00, 48, 8B, D8, 48, 85, C0, 75, 0A, B8, FF, 00, 00, 00, E9, 5A, 02, 00, 00, C7, 00, 94, 00, 00, 00, 48, 8B, C8, FF, 15, 34, 91, 01, 00, 85, C0, 75, 1E, FF, 15, 3A, 92, 01, 00, 48, 8B, C8, 4C, 8B, C3, 33, D2, FF, 15, 1C, 92, 01, 00, B8, FF, 00, 00, 00, E9, 29, 02, 00, 00, 8B, 43, 10, 89, 05, 45, 59, 03, 00, 8B...
 
[+]

Entropy:
6.2091

Code size:
140 KB (143,360 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PWRISOVM.EXE

Command:
C:\Program Files\poweriso\pwrisovm.exe -startup