Profwiz.exe

User Profile Wizard

ForensiT Limited

Publisher:
ForensiT Limited  (signed and verified)

Product:
User Profile Wizard

Description:
ForensiT User Profile Wizard

Version:
3.5.1160.0

MD5:
04096023c9a0b1fee894d254950fb650

SHA-1:
1cd790f5f5a7ab16e59c1c50b407ec94f8eb66b9

SHA-256:
6292803d1982cdd5d791df378203e1cf79082b444437a773d74707ddf32d8749

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 9:21:40 PM UTC  (today)

File size:
574.8 KB (588,568 bytes)

Product version:
3.5.1160.0

Copyright:
Copyright © ForensiT 2002-2011

Original file name:
Profwiz.exe

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
3/25/2009 10:00:00 AM

Valid to:
5/15/2012 9:59:59 AM

Subject:
CN=ForensiT Limited, OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=ForensiT Limited, L=Chatham, S=Kent, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
47FDFF90411A6950291B54D9846B7CF8

File PE Metadata
Compilation timestamp:
8/26/2011 12:58:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:vesHZ4Ad9Oo9RM4lJODXQvesBXCMNwRVA+C+NoSQBV8X+Ku:vbndJ9RMwODXQ2sgMNwRVRC+NoxKu

Entry address:
0xBD5A

Entry point:
E8, 56, 51, 00, 00, E9, 89, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 4A, F1, FF, FF, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 34, F1, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 8B, FF, 56, 57, 8B, F0, 68, 01, 01, 00, 00, 33, FF, 8D, 46...
 
[+]

Entropy:
6.4973

Code size:
87 KB (89,088 bytes)

Scan Profwiz.exe - Powered by Reason Core Security