viview.exe

ViView PhotoViewer

Flyingbird Technology Limited

The application viview.exe by Flyingbird Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program ViView by Flyingbird Technology Limited..
Publisher:
Flyingbird Technology Limited  (signed and verified)

Product:
ViView PhotoViewer

Version:
1.006

MD5:
c7a612a1c6bd4adbaad0bf96b127adb8

SHA-1:
59455a755a7792db95cc39c0a60e5d65009be5bb

SHA-256:
bdc1b1e2fe3ba6bdfa6f56a8308ddbc3316d81e6f963889d385e50b963719924

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 9:30:17 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX.FlyingbirdTechnology (M)
16.1.14.22

File size:
4.9 MB (5,129,848 bytes)

Product version:
1.006

Copyright:
Copyright (C) 2013

Original file name:
rrphotoviewer.rc

File type:
Executable application (Win32 EXE)

Language:
Arabic (Syria)

Common path:
C:\Program Files\viview\viview.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/31/2013 11:17:31 AM

Valid to:
8/1/2014 11:17:31 AM

Subject:
CN=Flyingbird Technology Limited, O=Flyingbird Technology Limited, L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219C80305D6E9F5989212C98615553D346

File PE Metadata
Compilation timestamp:
3/3/2014 6:31:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
49152:/m7Af4fmlBK3fQZ9LFBB+KdEmYaIHwaHDOvqi3Wr7a6okcsxj3AiBI/ilVKFTOXC:/m7AfimMfQ7EK+/HDOyH6/4VJX0Bx

Entry address:
0x2FACC2

Entry point:
E8, A6, FD, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, A5, C2, D3, E0, C3, 8B, D0, 33, C0, 80, E1, 1F, D3, E2, C3, 33, C0, 33, D2, C3, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 4F, AD, 6F, 00, 6A, 00, FF...
 
[+]

Entropy:
6.5854

Code size:
3.6 MB (3,805,184 bytes)

The file viview.exe has been discovered within the following program.

ViView  by Flyingbird Technology Limited.
About 3% of users remove it
 
Powered by Should I Remove It?

Remove viview.exe - Powered by Reason Core Security