schagent.exe

CyberScrub Security

CyberScrub LLC

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘CyberScrub CyberScrub Security Scheduler Agent’.
Publisher:
CyberScrub LLC  (signed and verified)

Product:
CyberScrub (R) Security (TM)

Description:
Sheduler Service Agent

Version:
1.0.0.139

MD5:
b191d42763b52c1f3457bf5d68ec9472

SHA-1:
bfc266d4e7d21860d1e2785d0b0ec8446cd73a05

SHA-256:
678e29df31d20e7582fdd7d6e00654ace901bd8c311ee9938487a4d3603bcde7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:05:15 AM UTC  (today)

File size:
525.2 KB (537,816 bytes)

Product version:
1.0.0.855

Copyright:
Copyright © 2012 CyberScrub Technologies LLC

Trademarks:
Security (TM) is a trademark of CyberScrub LLC

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\cyberscrub security\schagent.exe

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
2/3/2011 5:00:00 PM

Valid to:
2/3/2013 4:59:59 PM

Subject:
CN=CyberScrub LLC, O=CyberScrub LLC, STREET=5100 Highlands Pkwy SE, L=Smyrna, S=GA, PostalCode=30082, C=US

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
0089492AB9F80DC640BCB6D989FDAFFBA1

File PE Metadata
Compilation timestamp:
3/27/2012 1:44:51 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:ZVCFLq7oLYcvlZF91hdvZMrxiqWX2888888888888W88888888888l:nYL2q3ljDCiqWM

Entry address:
0x6BACC

Entry point:
55, 8B, EC, 83, C4, F0, 53, 56, B8, 34, A3, 46, 00, E8, D2, C9, F9, FF, 8B, 35, 48, DD, 46, 00, B8, 64, BB, 46, 00, E8, DA, 98, FF, FF, 8B, 06, E8, C3, 73, FF, FF, B8, 9C, BB, 46, 00, E8, C9, 98, FF, FF, B2, 01, A1, B8, 54, 46, 00, E8, 19, 9A, FF, FF, 8B, D8, B8, F8, BB, 46, 00, E8, B1, 98, FF, FF, EB, 22, 8B, 06, E8, 7C, 72, FF, FF, B8, 30, BC, 46, 00, E8, 9E, 98, FF, FF, 8B, C3, E8, 5B, 9A, FF, FF, 68, F4, 01, 00, 00, E8, 6D, D0, F9, FF, 8B, 06, 80, B8, A0, 00, 00, 00, 00, 74, D3, B8, 78, BC, 46, 00, E8...
 
[+]

Entropy:
6.4900

Developed / compiled with:
Microsoft Visual C++

Code size:
425 KB (435,200 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
CyberScrub CyberScrub Security Scheduler Agent

Command:
C:\Program Files\cyberscrub security\schagent.exe


Scan schagent.exe - Powered by Reason Core Security