{"id":5168,"date":"2015-03-02T20:21:52","date_gmt":"2015-03-02T20:21:52","guid":{"rendered":"http:\/\/www.freefixer.com\/b\/?p=5168"},"modified":"2015-03-09T20:22:14","modified_gmt":"2015-03-09T20:22:14","slug":"giner-tech-inc-hpnotify-exe-cmdshell-exe-protectservice-exe","status":"publish","type":"post","link":"https:\/\/www.freefixer.com\/b\/giner-tech-inc-hpnotify-exe-cmdshell-exe-protectservice-exe\/","title":{"rendered":"Giner Tech Inc &#8211; HPNotify.exe, CmdShell.exe and ProtectService.exe"},"content":{"rendered":"<p>Welcome! Just a short note on a publisher called <strong>Giner Tech Inc<\/strong>. Did you find some processes\u00a0called <a href=\"http:\/\/www.freefixer.com\/library\/file\/ProtectService.exe-170897\/\">HPNotify.exe<\/a>, <a href=\"http:\/\/www.freefixer.com\/library\/file\/CmdShell.exe-170898\/\">CmdShell.exe<\/a> or <a href=\"http:\/\/www.freefixer.com\/library\/file\/HPNotify.exe-170961\/\">ProtectService.exe<\/a>, located in folder called XTab,\u00a0running in the Windows Task Manager?<a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/HPNotify.exe-CmdShell.exe-ProtectService.exe-Giner-Tech.png\"><img loading=\"lazy\" class=\"alignnone wp-image-5171 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/HPNotify.exe-CmdShell.exe-ProtectService.exe-Giner-Tech.png\" alt=\"HPNotify.exe CmdShell.exe ProtectService.exe signed by Giner Tech\" width=\"567\" height=\"432\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/HPNotify.exe-CmdShell.exe-ProtectService.exe-Giner-Tech.png 567w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/HPNotify.exe-CmdShell.exe-ProtectService.exe-Giner-Tech-300x228.png 300w\" sizes=\"(max-width: 567px) 100vw, 567px\" \/><\/a><\/p>\n<p>You can\u00a0view the digital signature for a file by looking at a file&#8217;s properties in Windows Explorer. Here&#8217;s a screenshot of the <strong>Giner Tech Inc<\/strong> certificate embedded in the CmdShell.exe file:<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-certificate.png\"><img loading=\"lazy\" class=\"alignnone wp-image-5170 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-certificate.png\" alt=\"Giner Tech Inc certificate on CmdShell.exe\" width=\"410\" height=\"417\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-certificate.png 410w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-certificate-294x300.png 294w\" sizes=\"(max-width: 410px) 100vw, 410px\" \/><\/a><\/p>\n<p>Giner Tech Inc seems to be located in Wilmington, Delaware, US according to the certificate.<\/p>\n<p>So what&#8217;s <a title=\"How To Scan a File for Viruses with VirusTotal\" href=\"http:\/\/www.freefixer.com\/b\/scan-files-for-viruses-virustotal\/\">VirusTotal<\/a>&#8216;s view on the Giner Tech Inc files? Avira detects ProtectService.exe as <strong>PUA\/SearchProtect.EH<\/strong>, Baidu-International reports <strong>PUA.Win32.ELEX.BM<\/strong>, K7GW calls it <strong>Trojan ( 004b5c571 )<\/strong>, Malwarebytes classifies it as <strong>PUP.Optional.XTab.A<\/strong> and Sophos detects it as <strong>Generic PUA JL<\/strong>. The detection rate is 46%.<\/p>\n<p><a href=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-anti-virus-report.png\"><img loading=\"lazy\" class=\"alignnone wp-image-5169 size-full\" src=\"http:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-anti-virus-report.png\" alt=\"Giner Tech Inc anti-virus report for ProtectService.exe\" width=\"744\" height=\"433\" srcset=\"https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-anti-virus-report.png 744w, https:\/\/www.freefixer.com\/b\/wp-content\/uploads\/2015\/03\/Giner-Tech-Inc-anti-virus-report-300x174.png 300w\" sizes=\"(max-width: 744px) 100vw, 744px\" \/><\/a><\/p>\n<p>Hope that helped you figure out what those files are about. Thank you for reading.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Welcome! Just a short note on a publisher called Giner Tech Inc. Did you find some processes\u00a0called HPNotify.exe, CmdShell.exe or ProtectService.exe, located in folder called XTab,\u00a0running in the Windows Task Manager? You can\u00a0view the digital signature for a file by looking at a file&#8217;s properties in Windows Explorer. Here&#8217;s a screenshot of the Giner Tech &hellip; <a href=\"https:\/\/www.freefixer.com\/b\/giner-tech-inc-hpnotify-exe-cmdshell-exe-protectservice-exe\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Giner Tech Inc &#8211; HPNotify.exe, CmdShell.exe and ProtectService.exe<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[54],"tags":[510,511],"_links":{"self":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/5168"}],"collection":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/comments?post=5168"}],"version-history":[{"count":2,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/5168\/revisions"}],"predecessor-version":[{"id":5173,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/posts\/5168\/revisions\/5173"}],"wp:attachment":[{"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/media?parent=5168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/categories?post=5168"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.freefixer.com\/b\/wp-json\/wp\/v2\/tags?post=5168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}