~cbu_tmp.exe

Macro Toolworks Products Family

Pitrinec Petr

Publisher:
Pitrinec Software  (signed by Pitrinec Petr)

Product:
Macro Toolworks Products Family

Description:
Macro Toolworks Products Family Uninstall

Version:
1, 0, 0, 1

MD5:
7228e0d5bc2b8f62cb249cdbf317ab84

SHA-1:
8937aa4a44a72282600b9333aaebe61c34c93e16

SHA-256:
3ec02fb6941e4c8f783f919a017ae00da4d6b7e7cc937e60c447ef59347277fc

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/18/2024 10:30:34 PM UTC  (today)

File size:
1.5 MB (1,523,160 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1999-2014 Pitrinec Softwarwe

Original file name:
uninstall.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\~cbu_tmp.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/16/2013 5:09:30 AM

Valid to:
10/28/2015 11:29:47 AM

Subject:
E=support@pitrinec.com, CN=Pitrinec Petr, O=Pitrinec Petr, L=Cerveni Kostelec, S=Hradec Kralove, C=CZ

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112170521506291169F7ECCBB6E362F2DB5A

File PE Metadata
Compilation timestamp:
4/5/2014 9:03:29 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:jYs2buIHOvHirhC1nq5KLY3OlwO9oqfzi6d4YtEU0oQrN9jS1Lj999aqeOgw1/gc:j2vHOvHirAnqsE3OlwYpf+670oSN9uvd

Entry address:
0xF982C

Entry point:
E8, 4B, B5, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 20, BD, 56, 00, 00, 75, 18, E8, CF, AC, 00, 00, 6A, 1E, E8, 19, AB, 00, 00, 68, FF, 00, 00, 00, E8, E0, 10, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 20, BD, 56, 00, FF, 15, 64, E2, 51, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 28, BD, 56, 00, 74, 0D, 53, E8, 8E, B5, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, DA, 06, 00, 00, 89, 30, E8, D3, 06, 00, 00, 89...
 
[+]

Entropy:
6.3892

Code size:
1.1 MB (1,166,848 bytes)

Scan ~cbu_tmp.exe - Powered by Reason Core Security