Banco de Dados de Ameaças Spyware Program:Win32/PowerRegScheduler

Program:Win32/PowerRegScheduler

Por JubileeX em Spyware
Traduzir Para:

Cartão de pontuação de ameaças

Popularity Rank: 4,143
Nível da Ameaça: 10 % (Normal)
Computadores infectados: 2,950
Visto pela Primeira Vez: December 23, 2010
Visto pela Última Vez: December 21, 2025
SO (s) Afetados: Windows


O Program:Win32/PowerRegScheduler é um sistema de registro de produtos, normalmente encontrado nos computadores que executam os sistemas operacionais do Windows. Ele pode ser usado para coletar dados demográficos para os vendedores que usam o PowerRegScheduler como lembrete de registro de produto. O Program:Win32/PowerRegScheduler é capaz de coletar dados sensíveis, tais com nome de usuário, número de série de produtos e muito mais. Os dados coletados são então transmitidos para os servidores do PowerRegScheduler e disponibilizados para o fabricante do produto adquirido.

Outros Nomes

7 fornecedores de segurança sinalizaram este arquivo como malicioso.

Antivirus Vendor Detecção
AhnLab-V3 Trojan/Win32.Muwid
TrendMicro PAK_Generic.001
McAfee Artemis!A3300908EA6C
Panda Suspicious file
Ikarus Win32.SuspectCrc
Microsoft Program:Win32/PowerRegScheduler
eSafe Virus in password protected archive

SpyHunter detecta e remove Program:Win32/PowerRegScheduler

Detalhes Sobre os Arquivos do Sistema

Program:Win32/PowerRegScheduler pode criar o(s) seguinte(s) arquivo(s):
# Nome do arquivo MD5 Detecções
1. PalmDesktopSetup.exe 12ab0e4abe34fc252301ccacd7ab4581 160
2. wins.exe a3300908ea6c58551c8a2ae704658244 5

Relatório de análise

Informação geral

Family Name: PUP.PowerRegScheduler
Signature status: No Signature

Known Samples

MD5: 42c11bcd36fef54f359385a03a083abd
SHA1: 307249adc73341faac3ec79289015cc223f60688
SHA256: 5561E604E007D1BB084212B31778C0F65E2FDFE6269F090D12F626E37488C91D
Tamanho do Arquivo: 2.34 MB, 2338816 bytes
MD5: 95d7477e08d661fcd4ecb71218e973e1
SHA1: 0b557ce40ccff2c0b40cb7027e9be0b8fc518a65
SHA256: F6191017C834171385FD0CEBA6547C81360A257546A71F771E381C7B267732D4
Tamanho do Arquivo: 2.56 MB, 2564096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Nome Valor
Company Name
  • Leader Technologies/Franklin Covey
  • Leader Technologies/MathSoft
File Description
  • MathSoft
  • Planner for the Palm
File Version
  • 3.00
  • 1, 0, 0, 1
Internal Name
  • FCDD
  • MSFT
Legal Copyright
  • Copyright (C) 1999
  • Copyright (C) 2000
Original Filename
  • FCDD.exe
  • MSFT.EXE
Product Name PowerReg
Product Version
  • 3.00
  • 1, 0, 0, 1

File Traits

  • x86

Block Information

Total Blocks: 2,427
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2,207
Unknown Blocks: 220

Visual Map

0 ? 0 0 0 ? ? 0 ? 0 0 0 0 ? 0 ? ? ? ? 0 0 0 0 0 0 0 1 0 ? 0 0 ? 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 1 0 ? 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 ? ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 0 0 ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 ? ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 1 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 1 0 0 0 0 ? ? 0 0 ? ? ? ? 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Tendendo

Mais visto

Carregando...