idp.exe

Li Junxi

Publisher:
Li Junxi  (signed and verified)

MD5:
62583d97ec56ef4912d91890a9c23a69

SHA-1:
b4894b3fef1bbd94bbfbe6244f44ca2af4a4485b

SHA-256:
951a26bb7a52747b7e6e3cd90704551a817e1076c273b16771b0e8d135710592

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 3:01:17 AM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Worm.Win32.Dropper.RA
16263

Trend Micro House Call
TROJ_GEN.F47V1026
7.2.238

File size:
2 MB (2,082,568 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\id photo maker\idp.exe

Digital Signature
Signed by:

Authority:
StartCom Ltd.

Valid from:
10/9/2011 12:14:17 PM

Valid to:
10/9/2013 11:29:05 PM

Subject:
E=alex_li_sw@hotmail.com, CN=Li Junxi, L=GuangZhou, S=Guangdong, C=CN, Description=532724-nuJF0mZQas2sZjWm

Issuer:
CN=StartCom Class 2 Primary Intermediate Object CA, OU=Secure Digital Certificate Signing, O=StartCom Ltd., C=IL

Serial number:
044C

File PE Metadata
Compilation timestamp:
8/1/2010 10:39:17 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:D1zaHExS6i6WLizWWWK5vkXuv5DRLyfdYNirjehv/6s1nmTaWjudtl/G+KuDzhYF:DdaH/3Wj5cXuv5Qei4KELd7/xzuqnMf

Entry address:
0xBA60A

Entry point:
55, 8B, EC, 6A, FF, 68, F0, AD, 55, 00, 68, 38, F3, 4B, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, B0, C3, 4D, 00, 33, D2, 8A, D4, 89, 15, 38, 63, 59, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 34, 63, 59, 00, C1, E1, 08, 03, CA, 89, 0D, 30, 63, 59, 00, C1, E8, 10, A3, 2C, 63, 59, 00, 6A, 01, E8, 68, 4C, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 13, 4A, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Entropy:
6.9327

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
873.5 KB (894,464 bytes)

The file idp.exe has been discovered within the following program.

ID Photo Maker 3.2 Build 1118  by ID Photo Maker Team
www.idphotomaker.com
About 3% of users remove it
 
Powered by Should I Remove It?

Scan idp.exe - Powered by Reason Core Security