installer.exe

Peters Software GmbH

This is a setup and installation application. This is the uninstaller utility registered in the Windows Control Panel for the program EXAM 11 by Peters Software. The file has been seen being downloaded from activation.peterssoftware.eu.
Publisher:
Peters Software GmbH  (signed and verified)

MD5:
d52c1805e821a4440a6f74bbffd3e2c6

SHA-1:
66e043a4b882743726e92aae5fb6bfa0adc036a4

SHA-256:
f49610be1413f678dfb4e6b95348aabb4d58b980f4c3a8a47f398720608eed40

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/29/2024 11:25:40 PM UTC  (a few moments ago)

File size:
7.4 MB (7,777,160 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\peterssoftware\installer.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/26/2015 2:00:00 AM

Valid to:
5/26/2018 1:59:59 AM

Subject:
CN=Peters Software GmbH, O=Peters Software GmbH, STREET=An den Kaulen 26, L=Köln, S=NRW, PostalCode=50769, C=DE

Issuer:
CN=COMODO RSA Code Signing CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
7E615BE4FDE005D206C752BD39555FA9

File PE Metadata
Compilation timestamp:
8/4/2015 10:14:50 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.22

Entry address:
0x1290

Entry point:
55, 89, E5, 83, EC, 08, C7, 04, 24, 02, 00, 00, 00, FF, 15, 8C, 22, 41, 00, E8, A8, FE, FF, FF, 90, 8D, B4, 26, 00, 00, 00, 00, 55, 8B, 0D, C4, 22, 41, 00, 89, E5, 5D, FF, E1, 8D, 74, 26, 00, 55, 8B, 0D, B0, 22, 41, 00, 89, E5, 5D, FF, E1, 90, 90, 90, 90, 55, BA, 80, 00, 00, 00, 89, E5, 57, 31, C0, 8D, BD, E8, FE, FF, FF, 56, 53, 81, EC, 1C, 01, 00, 00, 89, 54, 24, 08, 89, 44, 24, 04, 89, 3C, 24, E8, CF, 57, 00, 00, 89, 7C, 24, 04, C7, 04, 24, 18, 00, 00, 00, E8, 67, 0D, 00, 00, 85, C0, 0F, 84, 7C, 00, 00...
 
[+]

Packer / compiler:
MingWin32

Code size:
23.5 KB (24,064 bytes)

Program Uninstaller
Program name:
EXAM 11

Display publisher:
Peters Software

Display version:
1.0

Uninstall string:
C:\Program Files\PetersSoftware\installer.exe


The file installer.exe has been seen being distributed by the following URL.

http://activation.peterssoftware.eu/activation/.../installer.exe

Scan installer.exe - Powered by Reason Core Security