tmp0067262a

Home'Bank Offline Plus 5.00 (VIMAIRE)

ING BELGIE NV

This is installed with Off-linediensten van Home'Bank 5.21.
Publisher:
ING  (signed by ING BELGIE NV)

Product:
Home'Bank Offline Plus 5.00 (VIMAIRE)

Version:
5.21.0001

MD5:
2428165ccd043229dcb8025df3698139

SHA-1:
f5bc7dd60f7f7ad344cd13d69e07f4e4cd54edd6

SHA-256:
d7ca24dcd7911bddff7af474ca04102f4286b6d5821baef25506b3f9c0c5969f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:17:47 PM UTC  (today)

File size:
12.1 MB (12,641,808 bytes)

Product version:
5.21.0001

Copyright:
Copyright ING 2011

Original file name:
hboff.exe

Language:
English (United States)

Common path:
C:\windows\temp\tmp000069d7\tmp0067262a

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
2/17/2010 1:00:00 AM

Valid to:
2/18/2012 12:59:59 AM

Subject:
CN=ING BELGIE NV, OU=Authenticode for Home'Bank applications, O=ING BELGIE NV, L=Brussels, S=Brussels, C=BE

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
4AD61303A8188EAE99574E8E3A6B24E2

File PE Metadata
Compilation timestamp:
9/13/2011 2:45:46 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
393216:B2ES2xMPY4dS6VyKZiJ45UZPVZUHfe5ZL9q7qtSMHc+p16F9GEjE7ZGOr8WS8nSt:B2ES2xMPY4dS6VyKZiJ4qZPVZV5ZL9qJ

Entry address:
0x45EFC

Entry point:
68, 64, 82, 44, 00, E8, F0, FF, FF, FF, 00, 00, 60, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 38, 00, 00, 00, 70, 01, 0A, 93, 45, 5F, 78, 47, 9E, 74, 96, 16, 1F, EA, 85, ED, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 47, D6, A1, 46, 98, 04, 48, 42, 4F, 46, 46, 00, 32, 98, 48, 6F, 6D, 65, 62, 61, 6E, 6B, 20, 4F, 66, 66, 6C, 69, 6E, 65, 20, 50, 6C, 75, 73, 20, 35, 2E, 30, 30, 00, E1, 00, A0, C9, 0F, 00, FC, 30, 00, 79, 00, 79, 00, D8, 00, 00, 00, A8, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 3B, 02, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
12 MB (12,578,816 bytes)

The file tmp0067262a has been discovered within the following program.

www.ing.be
About 3% of users remove it
 
Powered by Should I Remove It?

Scan tmp0067262a - Powered by Reason Core Security