PMB.exe

Pando Media Booster

Pando Networks, Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Pando Media Booster’. This is installed with Pando Media Booster.
Publisher:
Pando Networks, Inc.  (signed and verified)

Product:
Pando Media Booster

Version:
2,3,2,5

MD5:
1a46fc88cf56331839175a1a1bebccee

SHA-1:
fcfeeb159e2df24bd1dac8662fc1998ae32a7004

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 4:39:35 PM UTC  (today)

File size:
2.8 MB (2,919,608 bytes)

Product version:
2,3,2,5

Copyright:
Copyright (C) 2007-2009, Pando Networks Inc.

Original file name:
PMB.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\pando networks\media booster\pmb.exe

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
6/29/2009 8:00:00 PM

Valid to:
6/30/2010 7:59:59 PM

Subject:
CN="Pando Networks, Inc.", OU=Quality Assurance, O="Pando Networks, Inc.", L=New York, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
5D81FA21D0AFA48A98D5AC40680D50E9

File PE Metadata
Compilation timestamp:
10/7/2009 11:00:14 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:3UXvtYeBPLUsdizUOWQQXMmCDhqb0NrUOzbKE0H8ZAkkFnHHQx2eB647VvxG7T0/:QbA4ob0cQFHCB6yTG7TVGaPcuXyA/el

Entry address:
0x166F8F

Entry point:
E8, 34, 05, 00, 00, E9, 37, FD, FF, FF, CC, FF, 25, B4, 67, 5D, 00, 6A, 10, 68, 10, CA, 61, 00, E8, 60, 00, 00, 00, 33, C0, 89, 45, E0, 89, 45, FC, 89, 45, E4, 8B, 45, E4, 3B, 45, 10, 7D, 13, 8B, 75, 08, 8B, CE, FF, 55, 14, 03, 75, 0C, 89, 75, 08, FF, 45, E4, EB, E5, C7, 45, E0, 01, 00, 00, 00, C7, 45, FC, FE, FF, FF, FF, E8, 08, 00, 00, 00, E8, 67, 00, 00, 00, C2, 14, 00, 83, 7D, E0, 00, 75, 11, FF, 75, 18, FF, 75, E4, FF, 75, 0C, FF, 75, 08, E8, C0, FB, FF, FF, C3, CC, FF, 25, C0, 67, 5D, 00, 68, 65, 70...
 
[+]

Entropy:
6.5179

Code size:
1.8 MB (1,920,000 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Pando Media Booster

Command:
C:\Program Files\pando networks\media booster\pmb.exe


The file PMB.exe has been discovered within the following program.

Pando Media Booster  by Pando Networks Inc.
Pando Media Booster (PMB) is an application by Pando Networks that is used by game and software publishers to ensure safe, complete and speedy downloads of large files. PMB is primarily used to download MMORPGs.
www.pandonetworks.com/pando-media-booster-support-faq
51% remove it
 
Powered by Should I Remove It?

Scan PMB.exe - Powered by Reason Core Security