viview.exe

ViView PhotoViewer

Flyingbird Technology Limited

The application viview.exe by Flyingbird Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Flyingbird Technology Limited  (signed and verified)

Product:
ViView PhotoViewer

Version:
1.006

MD5:
f0fe2c77063f0d6ac8a77796ea51b377

SHA-1:
e038ee17497b2831c8c4cacd93f136241f6a7b54

SHA-256:
dc5a121622f2cb9908fe761caaeea5485d90fd798f5e3905c80e310a1d06fea0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 1:29:35 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.ELEX (M)
17.2.18.23

File size:
4.9 MB (5,129,880 bytes)

Product version:
1.006

Copyright:
Copyright (C) 2013

Original file name:
rrphotoviewer.rc

File type:
Executable application (Win32 EXE)

Language:
Polish (Poland)

Common path:
C:\Program Files\viview\viview.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
7/31/2013 10:17:31 AM

Valid to:
8/1/2014 10:17:31 AM

Subject:
CN=Flyingbird Technology Limited, O=Flyingbird Technology Limited, L=HongKong, S=HongKong, C=HK

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11219C80305D6E9F5989212C98615553D346

File PE Metadata
Compilation timestamp:
3/3/2014 5:31:56 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

Entry address:
0x2FACC2

Entry point:
E8, A6, FD, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, 80, F9, 40, 73, 15, 80, F9, 20, 73, 06, 0F, A5, C2, D3, E0, C3, 8B, D0, 33, C0, 80, E1, 1F, D3, E2, C3, 33, C0, 33, D2, C3, 55, 8B, EC, 51, 53, 8B, 45, 0C, 83, C0, 0C, 89, 45, FC, 64, 8B, 1D, 00, 00, 00, 00, 8B, 03, 64, A3, 00, 00, 00, 00, 8B, 45, 08, 8B, 5D, 0C, 8B, 6D, FC, 8B, 63, FC, FF, E0, 5B, C9, C2, 08, 00, 58, 59, 87, 04, 24, FF, E0, 55, 8B, EC, 51, 51, 53, 56, 57, 64, 8B, 35, 00, 00, 00, 00, 89, 75, FC, C7, 45, F8, 4F, AD, 6F, 00, 6A, 00, FF...
 
[+]

Code size:
3.6 MB (3,805,184 bytes)

Remove viview.exe - Powered by Reason Core Security