~cbu_tmp.exe

Macro Toolworks Products Family

Pitrinec Petr

Publisher:
Pitrinec Software  (signed by Pitrinec Petr)

Product:
Macro Toolworks Products Family

Description:
Macro Toolworks Products Family Uninstall

Version:
1, 0, 0, 1

MD5:
f4814a9a56093ad900a13218544babfa

SHA-1:
f38e563665d01286af75217affc073baa5c85a74

SHA-256:
f0455a02f8bfe6fcd3d86c76d62deddc31f5ebafe224b5e75f9abaf036f65cdf

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:54:11 AM UTC  (today)

File size:
1.5 MB (1,520,544 bytes)

Product version:
1, 0, 0, 1

Copyright:
Copyright (C) 1999-2013 Pitrinec Softwarwe

Original file name:
uninstall.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\~cbu_tmp.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
9/26/2012 8:29:47 AM

Valid to:
9/27/2013 8:29:47 AM

Subject:
E=support@pitrinec.com, CN=Pitrinec Petr, O=Pitrinec Petr, L=Cerveny Kostelec, S=Hradec Kralove, C=CZ

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219399D91DD78EDCEF1AE8AF9CC3B31474

File PE Metadata
Compilation timestamp:
7/6/2013 9:02:19 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:6gWDqC5sbR+tEE0rXSLpd7puYGCzMoc4KMyE2jQZcrLqwhSJFkJoziUATQpWa1lH:TWeAsbR+tELXS9d7puYrwotK5QZcrLqj

Entry address:
0xF913C

Entry point:
E8, 7B, B4, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 28, BD, 56, 00, 00, 75, 18, E8, FF, AB, 00, 00, 6A, 1E, E8, 49, AA, 00, 00, 68, FF, 00, 00, 00, E8, E0, 10, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 28, BD, 56, 00, FF, 15, 64, E2, 51, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 30, BD, 56, 00, 74, 0D, 53, E8, BE, B4, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, DA, 06, 00, 00, 89, 30, E8, D3, 06, 00, 00, 89...
 
[+]

Entropy:
6.3902

Code size:
1.1 MB (1,164,800 bytes)

Scan ~cbu_tmp.exe - Powered by Reason Core Security