herdprotectscan_install.exe

herdProtect Anti-Malware Scanner

Reason Company Software Inc.

Warning, this is an unsigned version of herdProtect and might be compromised. If you have this version on your PC please remove it and install a legitimate version from our website.
The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. The file has been seen being downloaded from download748.mediafire.com.
Publisher:
Reason Company Software Inc.

Product:
herdProtect Anti-Malware Scanner

Version:
1.0.0.0"

MD5:
10586c56ec6fe5bc7eb4eb5a98077c8a

SHA-1:
41625f4a12cc7ce70812f32527ac1e3ecbf52393

SHA-256:
f1e2543c26b205dd83998b07458ff60016720e8ccb76b7ac744d4f53c0445f30

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 9:12:01 AM UTC  (today)

File size:
333.1 KB (341,145 bytes)

Product version:
1.0.0.0"

Copyright:
Copyright Reason Company Software Inc.

Trademarks:
herdProtect is a Trademark of Reason Company Software Inc.

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\herdprotectscan_install.exe

File PE Metadata
Compilation timestamp:
5/19/2013 4:52:51 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:UoShflfVbexiq7PKHIBNrna2eV2oWr5tixra9R79O3fSdBNyZtrHB3:NqlfVbexiq7iojrnsV2o0urC7O3MmZr3

Entry address:
0x30DC

Entry point:
81, EC, 84, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 1C, C7, 44, 24, 10, 90, 91, 40, 00, 89, 5C, 24, 18, C6, 44, 24, 14, 20, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 8C, 72, 40, 00, 6A, 08, A3, 78, 3F, 42, 00, E8, 6E, 2D, 00, 00, A3, C4, 3E, 42, 00, 53, 8D, 44, 24, 38, 68, 60, 01, 00, 00, 50, 53, 68, 80, F4, 41, 00, FF, 15, 64, 71, 40, 00, 68, 80, 91, 40, 00, 68, C0, 36, 42, 00, E8, 18, 2A, 00, 00, FF, 15, 1C, 71, 40, 00, BD, 00, 90, 42, 00, 50, 55, E8, 06, 2A...
 
[+]

Entropy:
6.8485

Packer / compiler:
Nullsoft install system v2.x

Code size:
23 KB (23,552 bytes)

The file herdprotectscan_install.exe has been seen being distributed by the following URL.

Scan herdprotectscan_install.exe - Powered by Reason Core Security