regzookascheduler.exe

Scan regzookascheduler.exe - Powered by Reason Core Security
MD5:
5ca308435366bd2eabbb549f75718cf6

SHA-1:
a7b81fdd19d686b9b4ab1e9c9d0f09fc40384ce4

SHA-256:
9f6d6a4aa342ec63ebab6231fae7b2d76df4f917861ab2d492ef2bb46f68e708

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
12/6/2016 3:10:07 PM UTC  (today)

Scan engine
Detection
Engine version

Jiangmin
Trojan/Downloader.VBS.ifp
KV140610

File size:
396 KB (405,504 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\regzooka\regzookascheduler.exe

File PE Metadata
Compilation timestamp:
6/19/1992 5:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:Y10vjRADo/+GY8cJs0Qdrnlb3LZi9t3Q1zGp5ZBFXgROpFC1nc5FMzlolwm1t:9vVADo/+G0JibVqt324FXeOpk1c5OBC

Entry address:
0x4DF04

Entry point:
55, 8B, EC, 83, C4, F0, B8, 1C, DD, 44, 00, E8, 24, 7E, FB, FF, A1, CC, EF, 44, 00, 8B, 00, E8, 0C, DF, FF, FF, A1, CC, EF, 44, 00, 8B, 00, BA, 70, DF, 44, 00, E8, 0B, DB, FF, FF, A1, CC, EF, 44, 00, 8B, 00, C6, 40, 5B, 00, 8B, 0D, 04, EF, 44, 00, A1, CC, EF, 44, 00, 8B, 00, 8B, 15, 28, D5, 44, 00, E8, F0, DE, FF, FF, A1, CC, EF, 44, 00, 8B, 00, E8, 64, DF, FF, FF, E8, 2B, 5F, FB, FF, 00, 00, 00, FF, FF, FF, FF, 12, 00, 00, 00, 52, 65, 67, 5A, 6F, 6F, 6B, 61, 20, 53, 63, 68, 65, 64, 75, 6C, 65, 72, 00, 00...
 
[+]

Entropy:
6.5076

Developed / compiled with:
Microsoft Visual C++

Code size:
308 KB (315,392 bytes)

The file regzookascheduler.exe has been discovered within the following program.

RegZooka  by ZookaWare
Publisher's description - “Your computer’s registry is like the engine in your car; it drives everything in your computer. RegZooka scans your registry and removes files you don’t need, optimizes fragmented files, solves error messages like dll pop-ups and runtime errors.”
zookaware.com/regzooka
61% remove it
 
Powered by Should I Remove It?

Scan regzookascheduler.exe - Powered by Reason Core Security