RegInOut.exe

RegInOut System Utilities

SORCIM Technologies Pvt Ltd

The application RegInOut.exe by SORCIM Technologies Pvt has been detected as a potentially unwanted program by 6 anti-malware scanners. It runs as a scheduled task under the Windows Task Scheduler.
Publisher:
SORCIM Technologies  (signed by SORCIM Technologies Pvt Ltd)

Product:
RegInOut System Utilities

Version:
4.0.0.3000

MD5:
3b5aca2a24c6108bfc871b3be845e28d

SHA-1:
68f6fd9dd1007c09d36d34e6fbec8e901c1a21c6

SHA-256:
61cef79d990ce3b7b3e5c14011973a28a21ea31ba665194a2f6c4f324a6c9524

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 1:55:43 PM UTC  (today)

Scan engine
Detection
Engine version

Baidu Antivirus
Trojan.Win32.PCFresher
4.0.3.14926

Bkav FE
HW32.Laneul
1.3.0.4959

Comodo Security
ApplicUnwnt
19593

Dr.Web
riskware program Program.Optimizer.4
9.0.1.0269

ESET NOD32
Win32/Adware.PCFresher.A application
8.7.0.302.0

NANO AntiVirus
Riskware.Win32.Optimizer.dczuil
0.28.2.62286

File size:
7.8 MB (8,131,440 bytes)

Product version:
4.0.0.3000

Copyright:
RegInOut System Utilities

Original file name:
RegInOut.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\reginout system utilities\reginout.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/28/2013 12:00:00 AM

Valid to:
12/28/2014 11:59:59 PM

Subject:
CN=SORCIM Technologies Pvt Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=SORCIM Technologies Pvt Ltd, L=Rawalpindi, S=Punjab, C=PK

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2E9C2E7EA15D78EC37399C94A38F2CA9

File PE Metadata
Compilation timestamp:
11/29/2013 9:35:08 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:A52CjYOyblZ1GolJYHY9E3/l9qo3JCheTOko9pp:A5/jDybd9lGIE399qo3whQOkO

Entry address:
0x6E622

Entry point:
E8, 68, BB, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, A8, 38, 49, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 85, C0, 5F, 89, 45, FC, 5E, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 94, 03, 49, 00, C9, C2, 08, 00, B8, B0, AC, 47, 00, A3, 48, 08, 4B, 00, C7, 05, 4C, 08, 4B, 00, AC, A3, 47, 00, C7, 05, 50, 08, 4B, 00, 6A, A3, 47, 00, C7, 05, 54, 08, 4B, 00, 9E, A3, 47, 00, C7, 05, 58, 08...
 
[+]

Entropy:
4.5125

Code size:
572 KB (585,728 bytes)

Scheduled Task
Task name:
RegInOut Scheduled Scan - robert

Trigger:
Weekly (Runs weekly on Sundays at 03:00)

Description:
Schedule Scan


Remove RegInOut.exe - Powered by Reason Core Security