PPINUPDT.EXE

Protector Plus for Windows

Proland Software Pvt. Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Protector Plus InstaUpdate’.
Publisher:
Proland Software  (signed by Proland Software Pvt. Ltd.)

Product:
Protector Plus for Windows

Version:
8, 0, 68, 1

MD5:
191b677e6b477afbb216739f74a0474a

SHA-1:
ce8028906ce33ba2732e0443ca48fb23083d8913

SHA-256:
2f89aa13dacd93ed26660d9b555908cc715efefce6eb72b98579146e91536f24

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/23/2024 8:25:52 PM UTC  (today)

File size:
1.1 MB (1,159,848 bytes)

Product version:
8, 0, 68, 1

Copyright:
(c) Proland Software, 1991 - 2008

Trademarks:
Protector Plus

Original file name:
PPINUPDT.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
12/7/2006 12:00:00 AM

Valid to:
12/6/2008 11:59:59 PM

Subject:
CN=Proland Software Pvt. Ltd., OU=Secure Application Development, O=Proland Software Pvt. Ltd., L=Bangalore, S=Karnataka, C=IN

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
245198671971936C4AC247EFB1F201A9

File PE Metadata
Compilation timestamp:
8/25/2008 11:49:34 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
12288:kbf5c3zHMris51y0Y8OjFHUMTEVZCQQ8z5BpbFsIwbdZbA6eQn5k:qujsuszDOjFHiW+tF5

Entry address:
0x3896A

Entry point:
55, 8B, EC, 6A, FF, 68, 48, 86, 45, 00, 68, 08, 76, 43, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 24, 43, 45, 00, 33, D2, 8A, D4, 89, 15, B0, F0, 47, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, AC, F0, 47, 00, C1, E1, 08, 03, CA, 89, 0D, A8, F0, 47, 00, C1, E8, 10, A3, A4, F0, 47, 00, 6A, 01, E8, 4C, 25, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, C3, 00, 00, 00, 59, E8, 92, 43, 00, 00, 85, C0, 75, 08, 6A, 10, E8, B2, 00, 00, 00, 59, 33, F6, 89, 75...
 
[+]

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
332 KB (339,968 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Protector Plus InstaUpdate

Command:
C:\protec~1\ppinupdt.exe


Scan PPINUPDT.EXE - Powered by Reason Core Security