atd_fer.exe

Agenda Telefônica Digital

Nelson Luiz Dumbra

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘ATD_FER.exe’.
Publisher:
NOVA ERA Informática  (signed by Nelson Luiz Dumbra)

Product:
Agenda Telefônica Digital®

Version:
12.0.0.0

MD5:
a58e7d168b3ce6baa60b374e5a8af984

SHA-1:
384e2f62068d973c2b060115d5f559ff033acb87

SHA-256:
accd11733ab031db33201f5da40ca3b35f54dc7f6b5a8fc1749e4ce7c75f9ad2

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/26/2024 10:45:38 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Suspicious
20283

File size:
7.6 MB (8,019,104 bytes)

Product version:
12

Copyright:
Nelson Luiz Dumbra

Trademarks:
Agenda Telefônica Digital®

Original file name:
ATD.EXE

File type:
Executable application (Win32 EXE)

Language:
Brazilian Portuguese

Digital Signature
Authority:
COMODO CA Limited

Valid from:
10/23/2011 10:00:00 PM

Valid to:
10/23/2012 9:59:59 PM

Subject:
CN=Nelson Luiz Dumbra, O=Nelson Luiz Dumbra, STREET="Rua Vicente Castrequini, 3680", STREET=Jardim Planalto, L=Votuporanga, S=São Paulo, PostalCode=15501105, C=BR

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
009002D904566E3AB1AD23E1DD461E8B32

File PE Metadata
Compilation timestamp:
6/19/1992 7:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:sxINbM6iROj73Y1DOzo68ERGiUuchlCAPpmqbGrXrj66EPsxnm+Dea3qvuyAJRlU:SHuYo3vUuc3VBL+V6kX0WOzAv8N

Entry address:
0x630498

Entry point:
55, 8B, EC, 83, C4, F0, B8, 88, F6, A2, 00, E8, 94, 73, 9D, FF, A1, 34, 37, A4, 00, 8B, 00, 8B, 40, 30, BA, 01, 00, 00, 00, E8, A4, ED, FF, FF, 84, C0, 0F, 85, 80, 00, 00, 00, A1, 34, 37, A4, 00, 8B, 00, E8, E8, BD, A6, FF, A1, 34, 37, A4, 00, 8B, 00, 83, C0, 50, E8, 19, 4A, 9D, FF, 8B, 0D, 10, 30, A4, 00, A1, 34, 37, A4, 00, 8B, 00, 8B, 15, E4, 7F, A2, 00, E8, D9, BD, A6, FF, 8B, 0D, CC, 35, A4, 00, A1, 34, 37, A4, 00, 8B, 00, 8B, 15, 00, DD, A0, 00, E8, C1, BD, A6, FF, 8B, 0D, 30, 3E, A4, 00, A1, 34, 37...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
6.2 MB (6,485,504 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
ATD_FER.exe

Command:
C:\agenda telefônica digital\fernandópolis\atd_fer.exe


Scan atd_fer.exe - Powered by Reason Core Security