PPINUPDT.EXE

Protector Plus Professional for Windows

Proland Softwares Private Limited

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Protector Plus InstaUpdate’.
Publisher:
Proland Software  (signed by Proland Softwares Private Limited)

Product:
Protector Plus Professional for Windows

Version:
9, 0, 0, 2

MD5:
792083b72753f4005956b30485be1bc9

SHA-1:
083ebd8bb7582b053a23240bf3ed1726acf59d0b

SHA-256:
375bf66741dabe5b067cca466b9bdf7490dfcb7b71198bb081cf908b42d5c828

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 3:22:10 PM UTC  (today)

File size:
1.4 MB (1,475,216 bytes)

Product version:
9, 0, 0, 2

Copyright:
(c) Proland Software, 1991 - 2012

Trademarks:
Protector Plus

Original file name:
PPINUPDT.EXE

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/3/2012 1:00:00 AM

Valid to:
2/22/2013 12:59:59 AM

Subject:
CN=Proland Softwares Private Limited, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Proland Softwares Private Limited, L=Bangalore, S=Karnakata, C=IN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
60904A0573CF4C5EABC6A9995B79FB1D

File PE Metadata
Compilation timestamp:
7/31/2012 2:19:05 PM

OS version:
4.0

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:XorydS8E+jiwy6naKo4VPNYOhuQretzzW59qZmePUGMsVIYIKsCuAIPeuTKS5:YrydS8TmT6aZ4GVlbPUGMsV8BA6HX

Entry address:
0x8F360

Entry point:
48, 83, EC, 28, E8, 97, 3F, 01, 00, 48, 83, C4, 28, E9, 0E, FD, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 83, EC, 38, 48, C7, 44, 24, 20, 00, 00, 00, 00, E8, 2E, 40, 01, 00, 48, 83, C4, 38, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, 48, 8B, C1, 0F, B7, 10, 48, 83, C0, 02, 66, 85, D2, 75, F4, 48, 2B, C1, 48, D1, F8, 48, 83, E8, 01, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 66, 90, 66, 66, 66, 90, 66, 90, 48, 8B, C1, 48, F7, D9, 48, A9, 07, 00, 00, 00, 74, 0F, 66, 90...
 
[+]

Code size:
691.5 KB (708,096 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Protector Plus InstaUpdate

Command:
C:\protec~1\ppinupdt.exe


Scan PPINUPDT.EXE - Powered by Reason Core Security