flasher.exe

This is a setup program which is used to install the application. It runs as a scheduled task under the Windows Task Scheduler. The file has been seen being downloaded from atfupdate.atfsupport.com and multiple other hosts.
MD5:
8803db7f811096d718d8fa0b4d7bc812

SHA-1:
e066f8cc56f37ef2c792c7b736b5dd8879ad9726

SHA-256:
cd591783c59d59e53334e1f58556ff8854d31a74c98c0a98ad1366c9445fbd26

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
8/5/2025 7:51:19 AM UTC  (today)

File size:
334.1 KB (342,096 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\nokia\flasher\flasher.exe

File PE Metadata
Compilation timestamp:
10/6/2011 3:36:43 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.21

CTPH (ssdeep):
3072:PGrKneu9LnbLRSmIKOWx1RmbHowH0tc8B/Lh2tBguJyxww/FN1pYF6u1T5V4ZM2W:YuZbomuowx2juJyxdpYF11LmLNspqK

Entry address:
0x1160

Entry point:
55, 89, E5, 83, EC, 18, C7, 04, 24, 01, 00, 00, 00, FF, 15, E4, 32, 42, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 89, E5, 53, 83, EC, 14, 8B, 45, 08, 8B, 00, 8B, 00, 3D, 91, 00, 00, C0, 77, 3B, 3D, 8D, 00, 00, C0, 72, 4B, BB, 01, 00, 00, 00, C7, 44, 24, 04, 00, 00, 00, 00, C7, 04, 24, 08, 00, 00, 00, E8, 83, 7B, 01, 00, 83, F8, 01, 0F, 84, FF, 00, 00, 00, 85, C0, 0F, 85, AA, 00, 00, 00, 31, C0, 83, C4, 14, 5B, 5D, C2, 04, 00, 3D, 94, 00, 00, C0, 74, 59, 3D, 96, 00, 00, C0, 74, 1B, 3D, 93...
 
[+]

Code size:
96.5 KB (98,816 bytes)

Scheduled Task
Task name:
{647BC518-1E4A-43D1-874C-982BD6C377EC}

Trigger:
Registration (Runs on registration)


The file flasher.exe has been discovered within the following program.

Nokia Software Updater is a program designed to manage all installed Nokia programs on the user's PC and check for and update any new versions of the software if available. This service will run in the background when Windows starts and periodically check for updates.
www.nokia.com
7% remove it
 
Powered by Should I Remove It?

The file flasher.exe has been seen being distributed by the following 3 URLs.

Scan flasher.exe - Powered by Reason Core Security