ArdfryPSDCodec.dll

PSD Decoder

Ardfry Imaging, LLC

Publisher:
Ardfry Imaging, LLC  (signed and verified)

Product:
PSD Decoder

Version:
1.6.1.0

MD5:
8dc089c8163ab64220c7bda85c11ca32

SHA-1:
f18c583145ad74b1a8fedd04d96a3b92e62308f9

SHA-256:
4e13d2e383186a537d4ae77d5644b7ab78920694092a5a61f75697820888e21e

Scanner detections:
2 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/16/2018 9:06:14 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

File size:
695.3 KB (711,967 bytes)

Product version:
1.6.1.0

Copyright:
Copyright (c) Ardfry Imaging, LLC. All rights reserved.

Original file name:
ArdfryPSDCodec.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\Program Files\ardfryimaging\psd codec\ardfrypsdcodec.dll

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
4/19/2012 6:00:00 AM

Valid to:
4/21/2013 5:59:59 AM

Subject:
CN="Ardfry Imaging, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Ardfry Imaging, LLC", L=Ann Arbor, S=Michigan, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
34D0528F6116C9BFCD03CDF42E63B68E

Registration
CLSIDs:
{01EA983A-60B5-46c9-AA60-55139B4BF47E}, {0B17D800-AE60-40A5-AD5B-DE73645A66C6}, {3631AB20-5D08-46E2-9810-2F1068E83667}, {43341271-304D-40f0-81BB-EBE341997DF2}, {49CA2E8A-8AB1-477C-A35D-6A36729774BA}, {5A724A2A-F4B5-4449-8299-3EB467DEB642}

ProgIDs:
ArdfryPSDCodec.PSDBitmapDecoder.1, ArdfryPSDCodec.AIThumbnailProvider.1, ArdfryPSDCodec.AIExtractImage.1, ArdfryPSDCodec.PSDThumbnailProvider.1, ArdfryPSDCodec.AETExtractImage.1, ArdfryPSDCodec.AfterEffectsThumbProv.1, ArdfryPSDCodec.INDDExtractImage.1

COM registered:
Yes

File PE Metadata
Compilation timestamp:
1/24/2013 1:06:11 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x50175

Entry point:
E9, D3, FB, FE, FF, 83, 7D, 0C, 01, 75, 05, E8, 7A, BC, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 56, 57, 8B, 7D, 10, 8B, C7, 83, E8, 00, 0F, 84, B7, 14, 00, 00, 48, 0F, 84, 9F, 14, 00, 00, 48, 0F, 84, 6C, 14, 00, 00, 48, 0F, 84, 21, 14, 00, 00, 48, 0F, 84, 99, 13, 00, 00, 8B, 4D, 0C, 8B, 45, 08, 53, 6A, 20, 5A, E9, 32, 04, 00, 00, 8B, 30, 3B, 31, 74, 74, 0F, B6, 30, 0F, B6, 19, 2B, F3, 74, 13, 33, DB, 85, F6, 0F, 9F, C3, 8D, 74, 1B, FF, 85, F6...
 
[+]

Entropy:
6.7036

Packer / compiler:
Xtreme-Protector v1.05

Code size:
402.5 KB (412,160 bytes)

Approved Shell Extension
Name:
PSD Codec by Ardfry Imaging, LLC

CLSID:
{01EA983A-60B5-46c9-AA60-55139B4BF47E}


Scan ArdfryPSDCodec.dll - Powered by Reason Core Security