dd.exe

IP Labs GmbH

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Device Detection’.
Publisher:
IP Labs GmbH  (signed and verified)

Version:
1.14.1.0

MD5:
f2746b6854875eea590b0d30ec6a97d5

SHA-1:
ba8c20c9647dd0d3f39b0e78e020b9f09544c399

SHA-256:
1e406e36c8e61df07fdfca6bc110856dee63dd90b70afca8985fdcfc2e11293c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 12:10:47 AM UTC  (today)

File size:
837.1 KB (857,160 bytes)

Product version:
1.0

Copyright:
Copyright (C) 2012 by IP Labs GmbH

File type:
Executable application (Win32 EXE)

Language:
German (Germany)

Common path:
C:\Program Files\photosi\mycomposer\dd.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/18/2012 2:00:00 AM

Valid to:
6/18/2014 1:59:59 AM

Subject:
CN=IP Labs GmbH, OU=APPLICATION DEVELOPMENT, O=IP Labs GmbH, L=Bonn, S=Nordrhein-Westfalen, C=DE

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
152763E58C65752FD336C94C3BABCF16

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:N5FJs5dsBtFWAGvoQ/pGA9pAPX+ernZ6cvSajSoazJ/cN/vYFEO:3F6oB+AGvoypGAMOerZX5Mzlctuh

Entry address:
0xA7FAC

Entry point:
55, 8B, EC, 83, C4, F0, B8, D4, 65, 4A, 00, E8, BC, F1, F5, FF, E8, 9B, DB, FF, FF, E8, FE, C9, F5, FF, 8B, C0, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 02, 8D, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 32, 13, 8B, C0, 00, 8D, 40, 00, 00, 8D, 40, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
667 KB (683,008 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Device Detection

Command:
C:\Program Files\photosi\mycomposer\dd.exe


Scan dd.exe - Powered by Reason Core Security