ifns.exe

Sowsoft LLC

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Instant File Name Search’.
Publisher:
Sowsoft LLC  (signed and verified)

MD5:
16e550fa8a4ea2bfcba21aa99989d8e0

SHA-1:
1df50a4fa85083c206ecfee0bbdba5bdb3d97d23

SHA-256:
8e42c9825b31cd7078667448cee935a85b3e36dd53b4498cbca15586f7865e29

Scanner detections:
3 / 68

Status:
Clean  (3 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/25/2024 12:25:23 AM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
PUA.Packed.ASPack
0.98/17411

Comodo Security
Heur.Suspicious
7086

Quick Heal
(Suspicious) - DNAScan
4.16.11.00

File size:
477.9 KB (489,336 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
The USERTRUST Network

Valid from:
3/27/2007 3:00:00 AM

Valid to:
3/27/2009 1:59:59 AM

Subject:
CN=Sowsoft LLC, OU=(russian company name: ООО, O=Sowsoft LLC, STREET="Prospect Mira, d. 75, str. 1", L=Moscow, S=Moscow, PostalCode=129110, C=RU

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
6EB1EE0573C8BD55A954D41E07F04B65

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
6144:Rrvh4AY16mxzMXAV74DK56V0zYZwUQX/y04hEGvitOZZlmmInYAwn+aCP0vdZhh7:ROAIJsV04Bc/y0idvE0PfWPCZHBsYPFj

Entry address:
0x1000

Entry point:
68, 01, 00, 4C, 00, E8, 01, 00, 00, 00, C3, C3, 9A, 7E, 20, FA, 75, F6, FC, 7C, CA, C5, 6A, CC, F2, A4, 88, 18, 9B, 9A, AB, 95, AE, 08, 52, 82, BC, 00, 6C, 6D, D6, 07, 93, 3D, 8C, 65, AD, BC, 43, 80, D4, 99, 26, 35, 4A, 51, C4, 7C, 49, 51, 19, 42, 1D, AD, AB, 25, AF, 69, 01, 9D, 19, C6, 59, 36, 19, 97, F1, 05, 3A, F4, 88, 98, 3A, 26, 94, 89, B3, FA, 7F, 15, 96, 72, 1F, 69, DA, E3, 1A, 86, 76, B8, 0A, 26, FB, 83, A5, A7, B3, A2, CB, 53, 9B, 3E, 22, 3E, E6, 3D, 34, DB, 94, 79, 55, AC, 2E, 5D, 6A, 41, 66, 60...
 
[+]

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
595 KB (609,280 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Instant File Name Search

Command:
C:\portable\ifns\ifns.exe


Scan ifns.exe - Powered by Reason Core Security