Threat Database Spyware Program:Win32/PowerRegScheduler

Program:Win32/PowerRegScheduler

By JubileeX in Spyware

Threat Scorecard

Popularity Rank: 4,143
Threat Level: 10 % (Normal)
Infected Computers: 2,950
First Seen: December 23, 2010
Last Seen: December 21, 2025
OS(es) Affected: Windows

Program:Win32/PowerRegScheduler is a product registration system typically found on computers running Windows operating systems. Program:Win32/PowerRegScheduler can be used to collect demographic data for vendors who use PowerRegScheduler as a product registration reminder. Program:Win32/PowerRegScheduler is able to gather sensitive data such as your name, address, e-mail, product serial number and a lot more. The collected data is then transmitted to PowerRegScheduler servers and made available to the manufacturer of the purchased product.

Aliases

7 security vendors flagged this file as malicious.

Antivirus Vendor Detection
AhnLab-V3 Trojan/Win32.Muwid
TrendMicro PAK_Generic.001
McAfee Artemis!A3300908EA6C
Panda Suspicious file
Ikarus Win32.SuspectCrc
Microsoft Program:Win32/PowerRegScheduler
eSafe Virus in password protected archive

SpyHunter Detects & Remove Program:Win32/PowerRegScheduler

File System Details

Program:Win32/PowerRegScheduler may create the following file(s):
# File Name MD5 Detections
1. PalmDesktopSetup.exe 12ab0e4abe34fc252301ccacd7ab4581 160
2. wins.exe a3300908ea6c58551c8a2ae704658244 5

Analysis Report

General information

Family Name: PUP.PowerRegScheduler
Signature status: No Signature

Known Samples

MD5: 42c11bcd36fef54f359385a03a083abd
SHA1: 307249adc73341faac3ec79289015cc223f60688
SHA256: 5561E604E007D1BB084212B31778C0F65E2FDFE6269F090D12F626E37488C91D
File Size: 2.34 MB, 2338816 bytes
MD5: 95d7477e08d661fcd4ecb71218e973e1
SHA1: 0b557ce40ccff2c0b40cb7027e9be0b8fc518a65
SHA256: F6191017C834171385FD0CEBA6547C81360A257546A71F771E381C7B267732D4
File Size: 2.56 MB, 2564096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Leader Technologies/Franklin Covey
  • Leader Technologies/MathSoft
File Description
  • MathSoft
  • Planner for the Palm
File Version
  • 3.00
  • 1, 0, 0, 1
Internal Name
  • FCDD
  • MSFT
Legal Copyright
  • Copyright (C) 1999
  • Copyright (C) 2000
Original Filename
  • FCDD.exe
  • MSFT.EXE
Product Name PowerReg
Product Version
  • 3.00
  • 1, 0, 0, 1

File Traits

  • x86

Block Information

Total Blocks: 2,427
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2,207
Unknown Blocks: 220

Visual Map

0 ? 0 0 0 ? ? 0 ? 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 1 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 ? ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 ? ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 1 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 1 0 0 0 0 ? ? 0 0 ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...