adberdr80_en_us.exe

Netopsystems Size Optimizer

Adobe Systems, Incorporated

This is a setup program which is used to install the application. The file has been seen being downloaded from www.sadal.com.tr and multiple other hosts.
Publisher:
Adobe Systems, Incorporated  (signed and verified)

Product:
Netopsystems Size Optimizer(R)

Version:
1.0.0.54

MD5:
0ab5ce309f313ed028824251c798b35c

SHA-1:
eac3fe38b159632953a6ae13911343bcb624957a

SHA-256:
bb7eb62410ac1fdc5d5a2ddbf593ae5b7bee94918fc9da0a089063fa412e909e

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 8:34:29 AM UTC  (today)

File size:
20.8 MB (21,822,168 bytes)

Product version:
1.0.0.54

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\adobe reader 8\adberdr80_en_us.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/19/2006 1:00:00 AM

Valid to:
11/5/2009 11:59:59 PM

Subject:
CN="Adobe Systems, Incorporated", OU=Acrobat Engineering, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Adobe Systems, Incorporated", L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
270D755C9F5AC3B7DB61F50998287078

File PE Metadata
Compilation timestamp:
8/30/2006 3:51:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
5.12

CTPH (ssdeep):
393216:ohdus0UnUVMTD8yag7i0qywfgRgnopgSpl3cn7kALwzIKtv9ZOngzRsolkc4:oft3TDR7cdgRioNLGwAc0K7ZFXl4

Entry address:
0x7DA58

Entry point:
E8, 00, 00, 00, 00, 58, BB, 00, 00, 40, 00, 8B, B3, C0, 00, 00, 00, 8D, 04, 33, 48, 8A, 08, 80, F9, CC, 74, F8, 83, E8, 03, 8B, 10, 8B, B3, 6C, 01, 00, 00, 03, F3, 8D, BB, 00, 10, 00, 00, 57, 8B, CA, 2B, CE, 51, 56, E8, 6C, FE, FF, FF, 8D, 50, FC, 2B, 12, 8B, B2, 80, 00, 00, 00, 52, 03, F3, 8B, 46, 0C, 0B, C0, 74, 43, 03, C3, 50, E8, 48, 00, 00, 00, 8B, E8, 8B, 0E, 03, CB, 8B, 7E, 10, 03, FB, 8B, 01, 0B, C0, 74, 25, 60, A9, 00, 00, 00, 80, 74, 07, 25, FF, FF, FF, 7F, EB, 04, 8D, 44, 03, 02, 50, 55, E8, 17...
 
[+]

Code size:
79.2 KB (81,072 bytes)

The file adberdr80_en_us.exe has been discovered within the following programs.

2008 Edition Nurse's Drug Handbook  by Thomson Delmar Learning
www.delmarlearning.com
About 5% of users remove it
2009 Edition Nurses Drug Handbook  by Delmar Learning
www.DelmarLearning.com
About 5% of users remove it
EIVA Training  by EIVA
www.eiva.dk
About 9% of users remove it
Supreme Commander  by Gas Powered Games
Supreme Commander is a real-time strategy computer game focused on using a giant bipedal mech called an Armored Command Unit.
www.gaspowered.com
About 3% of users remove it
Thermo Xcalibur  by Thermo Fisher Scientific
www.thermo.com
About 1% of users remove it
 
Powered by Should I Remove It?

The file adberdr80_en_us.exe has been seen being distributed by the following 33 URLs.

http://www.sadal.com.tr/.../AdbeRdr80_en_US.exe

http://58.65.128.8:809/Softwares (A - F)/Softwares (A - F)/.../Adobe Acrobat Reader 8.0.exe

http://topfreedownloads.brothersoft.com/d.php?name=Adobe Reader&url=Adobe-Reader-8.0.exe&s=http://adobe-reader.brothersoft.com&d=2

http://192.168.2.83/AdbeRdr80_en_US.exe

http://www.tawjihi100.com/AdobeReader.exe

temp:AdbeRdr80_en_US.exe

http://software.oldversion.com/download.php?f=YTo1OntzOjQ6InRpbWUiO2k6MTQ2MzQwNzkxMztzOjI6ImlkIjtpOjQ3NjY7czo0OiJmaWxlIjtzOjIzOiI4LjBfQWRiZVJkcjgwX2VuX1VTLmV4ZSI7czozOiJ1cmwiO3M6NTI6Imh0dHA6Ly93d3cub2xkdmVyc2lvbi5jb20vd2luZG93cy9hY3JvYmF0LXJlYWRlci04LTAiO3M6NDoicGFzcyI7czozMjoiNTVjNjhlYzZjYjk0OWU1NzU5NTUzNmY3MjMxNjEzNzUiO30=

http://www.edupub.gov.lk/.../AdbeRdr80_en_US.exe

http://adobe-reader.brothersoft.com/.../Adobe-Reader-8.0.exe

http://58.65.128.4:809/Softwares (A - F)/Softwares (A - F)/.../Adobe Acrobat Reader 8.0.exe

http://10.1.3.31/erpimp/cms/.../Adobe Reader 8.exe

http://58.65.128.51:809/Softwares (A - F)/Softwares (A - F)/.../Adobe Acrobat Reader 8.0.exe

Latest 30 of 33 download URLs