pkz90010.exe

PKZIP for Windows 9.00.0010

PKWARE, Inc.

This is a setup and installation application. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
PKWARE, Inc   (signed by PKWARE, Inc.)

Product:
PKZIP for Windows 9.00.0010

Description:
Setup Launcher

Version:
9.00.0010

MD5:
fe426ea321cb429b73f1a966f8a32822

SHA-1:
3f057904cf3fff65f54c970aca8a4545ed77e48c

SHA-256:
d50bdf88ad4f2b1ee6463856075ed01af2074e35a2d4ad0bd40c8bb26a798f99

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
9/15/2025 10:06:56 AM UTC  (today)

File size:
8.1 MB (8,483,912 bytes)

Product version:
9.00.0010

Copyright:
Copyright (C) 2003 InstallShield Software Corp.

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
5/1/2005 9:00:00 PM

Valid to:
5/8/2006 8:59:59 PM

Subject:
CN="PKWARE, Inc.", OU=Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="PKWARE, Inc.", L=Brown Deer, S=Wisconsin, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
6F1E8AAD794D8408CABB09C045D64458

File PE Metadata
Compilation timestamp:
4/10/2003 6:51:10 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:p6FfGMkASVqV26hgDneSLYyCDFqO/sNAe+WJU:+uMkqE5LYPDFq8sNxU

Entry address:
0x1890C

Entry point:
55, 8B, EC, 6A, FF, 68, C8, 3B, 42, 00, 68, A4, B8, 41, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, C0, 31, 42, 00, 33, D2, 8A, D4, 89, 15, 18, EB, 42, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 14, EB, 42, 00, C1, E1, 08, 03, CA, 89, 0D, 10, EB, 42, 00, C1, E8, 10, A3, 0C, EB, 42, 00, 6A, 01, E8, C0, 1C, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, C0, 17, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
136 KB (139,264 bytes)

The file pkz90010.exe has been seen being distributed by the following 14 URLs.

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_en&type=PROGRAM&Expires=1452576425&Signature=M~GcH6TvxbMvkukGfQDlDcnDGbfCp71mIriVNjAbYDAfehm~vqhMCM0e0M5Lb~rVAasTzGiiZsxlQGV6~zRh3TB01Py~G2mKsDFA5owoZDraPloWTyS8wG-RlJR5XdnZlAJWZAnMhlO8uRtvhhFZl8JkX3kL5Lcauv8j5WA0WV8_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_en&type=PROGRAM&Expires=1452007787&Signature=IXQn0q1kt87rJZGa~wSbKNDbcPyxn990cEa0OdMyN9nIiNS7-YAqbf7uB1OS~wb7ImWDPQoe4JAR1Vxk1DIR1hHk3uIuyyj93jlOYXLJlgZSGp89X-7L7Nf1pJu7eTCGdztCGkQXM92nwhaCaRN37Q8UVK3fz~OCAHnMnZNKM9w_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_en&type=PROGRAM&Expires=1463866866&Signature=hfYHispmWRJPLFPo4edK5a7PQsOJGcHLLh49BaOa8WogXhP5ofDAXYjPTlKOLAVc503szVxwS~D0-c3f2Yz-yTb5t2EIZqlzVhrthU2QnLZ74WjX8ehXrfhCSsz8SNngr7WId84pD1SrYZfc0OlMUx2GXEQ5nXTN27sFoY0Yqcs_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_en&type=PROGRAM&Expires=1476748639&Signature=Ap7xdKqj78udVT5p8PFSgWh4M2KwHdNUhbja9MWliCUzK3~eXfUJdakmD6vcerHYP5xT2UYZ-4INj2ktfnqHTIBzcRbQC3iHK~~wWh3aSN3PoAnNwbSjRW-XzC97rIBTh68EE~dlasXvQyR1ki2nDjXzg25Y4WfNzk4T2UFVJGw_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_br&type=PROGRAM&Expires=1476104040&Signature=BAv6Lo~1exEyBYR-n5QyyBC4tnz0TlTGx2c0qep3LRBb-S-gP1DtVbqpGbDsecJ~q8sXz09C1BSCreK13iXkOumFMTxiv-V2jChvElpEA4eriEfTkt7Vfcka5OltkcJnZr87KdNeZs~VKFrlOX2IVdSYTRDVEo~lLIFSYNeCNjc_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_en&type=PROGRAM&Expires=1470814901&Signature=NA062vX7iu7UytXOH03VwqzUVzw5YmrsY2stXeFk2xkB7if02e3d-P9a8JF-UPoEqq7mcshv57L4MEaZfeHreTin1mMTBwDoaTBMPuhAxYzvdn7jrJkqfUQjz0fFSNfXsblSEZkgG~tzspXXPkk5EaHgme8iBpkoDCEkhRAn~8Y_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

http://gsf-cf.softonic.com/3f0/579/.../file?SD_used=0&channel=WEB&fdh=no&id_file=3015&instance=softonic_en&type=PROGRAM&Expires=1462180981&Signature=GfYtwt0HJh7OikkzAExWH07BsAZtHGX44b9Mm2BRMjTSS~gbluYV69R1y-Ac66A5uybwQCcyiTXWyWaJOnbI2qzJNgpHn0UpTEqpjJkywKpf5ozguGqOHRrQ6cn5B04AW2-PRrzhWEdwItQZlxbZ16zTxnZY2B-~zGlixFLCcmU_&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&filename=pkz90010.exe

Scan pkz90010.exe - Powered by Reason Core Security