photoframeshowwininstaller.exe

pfsinstaller

Likno Software

This is a setup and installation application. The file has been seen being downloaded from files.downloadnow.com.
Publisher:
Likno Software  (signed and verified)

Product:
pfsinstaller

Version:
1.00

MD5:
c9850ca3d655a939f2f87dedbd7ae437

SHA-1:
ce9f82f06c1a7504ef15e65a2313172bb2997489

SHA-256:
2f3f5b9174a47df280af5ba20668661b00baf88ea0236631bf247c935453b9e7

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 9:32:55 AM UTC  (today)

File size:
655.6 KB (671,328 bytes)

Product version:
1.00

Original file name:
pfsinstaller.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\application g downloader\photoframeshowwininstaller.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
5/27/2009 11:00:53 AM

Valid to:
5/28/2010 11:00:50 AM

Subject:
CN=Likno Software, O=Likno Software, L=Maroussi, S=Athens, C=GR

Issuer:
CN=GlobalSign ObjectSign CA, OU=ObjectSign CA, O=GlobalSign nv-sa, C=BE

Serial number:
0100000000012182C9B1E0

File PE Metadata
Compilation timestamp:
12/18/2009 9:19:58 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
6144:OtKI+YRncPac0BEoLYRncPac0BERBglrx4Kci/:b1PaRBEwPaRBE/6OKci/

Entry address:
0x1454

Entry point:
68, EC, 8E, 44, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 69, 22, 58, 26, 06, B6, 9A, 41, B4, 1F, 55, D7, 87, 2C, 64, B2, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 70, 66, 73, 69, 6E, 73, 74, 61, 6C, 6C, 65, 72, 00, 00, 00, 00, 00, 00, 00, 00, FF, CC, 31, 00, 01, 88, 6B, C0, 58, EA, 34, 4D, 47, A7, 14, C5, A0, 00, 1D, 26, 00, 9F, 8D, 1F, 5F, B1, AB, A6, 49, A6, 0F, 3B, 44, B4, E5, 8C, 9D, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
300 KB (307,200 bytes)

The file photoframeshowwininstaller.exe has been seen being distributed by the following URL.

Scan photoframeshowwininstaller.exe - Powered by Reason Core Security